SVG Optimizer Vulnerability in SVGO Library by SVG
CVE-2026-73650

8.2HIGH

Key Information:

Vendor

Svg

Status
Vendor
CVE Published:
13 August 2026

What is CVE-2026-73650?

The SVGO library, used for optimizing SVG files, contains a vulnerability in the removeScripts plugin that fails to adequately sanitize script elements in generated SVGs. This allows potentially executable content to remain in the optimized files, particularly due to the handling of namespaced or prefixed script elements like svg:script. If applications handle untrusted SVG inputs with this plugin enabled, it may result in unexpected script execution, potentially exposing sensitive user data such as local storage or cookies. This issue has been addressed in updated releases of SVGO.

Affected Version(s)

svgo >= 1.0.0, < 2.8.3 < 1.0.0, 2.8.3

svgo >= 3.0.0, < 3.3.4 < 3.0.0, 3.3.4

svgo >= 4.0.0, < 4.0.2 < 4.0.0, 4.0.2

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.