CVE-2026-73650: CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in svg svgo
A cross-site scripting (XSS) vulnerability exists in the SVGO library's removeScripts plugin, which fails to remove certain namespaced or prefixed script elements and is case sensitive to JavaScript URIs. This can allow executable scripts to remain in optimized SVG files, potentially enabling script execution when untrusted SVGs are processed and served. The issue affects versions from 1.0.0 up to but not including 2.8.3, 3.3.4, and 4.0.2, where it has been fixed.
AI Analysis
Technical Summary
SVGO is a Node.js library for optimizing SVG files. The vulnerability (CVE-2026-73650) involves the removeScripts plugin (removeScriptElement in versions 1 through 3) not removing namespaced or prefixed script elements such as <svg:script>. Additionally, in versions 3 and 4, the plugin matches JavaScript URIs case sensitively, allowing some executable content to remain in optimized SVGs. When applications process untrusted SVG input with this plugin enabled and serve the result, scripts can execute in the context of another user opening the SVG, potentially exposing local storage or cookies. The vulnerability is fixed in versions 2.8.3, 3.3.4, and 4.0.2.
Potential Impact
Exploitation of this vulnerability can lead to cross-site scripting attacks, allowing an attacker to execute scripts in the context of users viewing the SVG. This can result in exposure of sensitive information such as local storage or cookies. The CVSS score of 8.2 indicates a high severity with network attack vector, low attack complexity, no privileges required, user interaction required, scope changed, high confidentiality impact, low integrity impact, and no availability impact.
Mitigation Recommendations
A fix is available in SVGO versions 2.8.3, 3.3.4, and 4.0.2. Users and developers should upgrade to these or later versions to remediate the vulnerability. If upgrading is not immediately possible, avoid processing untrusted SVG input with the removeScripts plugin enabled or disable this plugin until patched versions are applied.
CVE-2026-73650: CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in svg svgo
Description
A cross-site scripting (XSS) vulnerability exists in the SVGO library's removeScripts plugin, which fails to remove certain namespaced or prefixed script elements and is case sensitive to JavaScript URIs. This can allow executable scripts to remain in optimized SVG files, potentially enabling script execution when untrusted SVGs are processed and served. The issue affects versions from 1.0.0 up to but not including 2.8.3, 3.3.4, and 4.0.2, where it has been fixed.
CVSS v3.1
Score 8.2high
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
SVGO is a Node.js library for optimizing SVG files. The vulnerability (CVE-2026-73650) involves the removeScripts plugin (removeScriptElement in versions 1 through 3) not removing namespaced or prefixed script elements such as <svg:script>. Additionally, in versions 3 and 4, the plugin matches JavaScript URIs case sensitively, allowing some executable content to remain in optimized SVGs. When applications process untrusted SVG input with this plugin enabled and serve the result, scripts can execute in the context of another user opening the SVG, potentially exposing local storage or cookies. The vulnerability is fixed in versions 2.8.3, 3.3.4, and 4.0.2.
Potential Impact
Exploitation of this vulnerability can lead to cross-site scripting attacks, allowing an attacker to execute scripts in the context of users viewing the SVG. This can result in exposure of sensitive information such as local storage or cookies. The CVSS score of 8.2 indicates a high severity with network attack vector, low attack complexity, no privileges required, user interaction required, scope changed, high confidentiality impact, low integrity impact, and no availability impact.
Mitigation Recommendations
A fix is available in SVGO versions 2.8.3, 3.3.4, and 4.0.2. Users and developers should upgrade to these or later versions to remediate the vulnerability. If upgrading is not immediately possible, avoid processing untrusted SVG input with the removeScripts plugin enabled or disable this plugin until patched versions are applied.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-08-13T14:04:09.604Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a7e0ff3bf8831d539a34e54
Added to database: 08/13/2026, 18:41:55 UTC
Last enriched: 08/13/2026, 18:56:26 UTC
Last updated: 08/13/2026, 21:59:19 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.