CVE-2026-73650
Last modified
CVE-2026-73650 is a high-severity vulnerability rated 8.2/10 on the CVSS scale. SVGO, short for SVG Optimizer, is a Node.js library and command-line application for optimizing SVG files. From version 1.0.0 until versions 2.8.3, 3.3.4, and 4.0.2, the removeScripts plugin, named removeScriptElement in versions 1 through 3, can leave executable content in optimized SVGs because it does not remove namespaced or prefixed script elements such as <svg:script> and, in versions 3 and 4, matches JavaScript URIs case sensitively. EPSS estimates a 0.24% chance of exploitation in the next 30 days.
Description
SVGO, short for SVG Optimizer, is a Node.js library and command-line application for optimizing SVG files. From version 1.0.0 until versions 2.8.3, 3.3.4, and 4.0.2, the removeScripts plugin, named removeScriptElement in versions 1 through 3, can leave executable content in optimized SVGs because it does not remove namespaced or prefixed script elements such as <svg:script> and, in versions 3 and 4, matches JavaScript URIs case sensitively. Applications that process untrusted SVG input with this plugin enabled and serve the result can allow scripts to execute when another user opens the SVG, exposing local storage or cookies. This issue is fixed in versions 2.8.3, 3.3.4, and 4.0.2.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| svg | svgo | >= 1.0.0, < 2.8.3; >= 3.0.0, < 3.3.4; >= 4.0.0, < 4.0.2 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-73650?
How severe is CVE-2026-73650?
How do I fix CVE-2026-73650?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-73645OpenZeppelin Confidential Contracts is an experimental libra…6.6
- CVE-2026-73646PostCSS takes a CSS file and provides an API to analyze and …7.5
- CVE-2026-73647Quasar Framework is a framework for building high-performanc…5.6
- CVE-2026-73648rails-html-sanitizer is responsible for sanitizing HTML frag…5.1
- CVE-2026-73649Velocity.js is a JavaScript implementation of the Apache Vel…9.8
- CVE-2026-7365IBM Operations Analytics - Log Analysis and IBM SmartCloud …7.8
- CVE-2026-73651TypeORM is a TypeScript and JavaScript ORM for Node.js that …5.7
- CVE-2026-73652vantage6 is an open-source infrastructure for privacy preser…7.1
- CVE-2026-73653Vitest is a testing framework powered by Vite. Prior to vers…9.4
- CVE-2026-73654Trigger.dev is a platform for building and deploying fully m…8.5
- CVE-2026-73655Trigger.dev is a platform for building and deploying fully m…7.4
- CVE-2026-73656Trigger.dev is a platform for building and deploying fully m…9.9
Are you affected by CVE-2026-73650?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
