Vulnerability Description
The package convert-svg-core before 0.6.2 are vulnerable to Remote Code Injection via sending an SVG file containing the payload.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Convert-Svg-Core Project | Convert-Svg-Core | < 0.6.2 |
Related Weaknesses (CWE)
References
- https://github.com/neocotic/convert-svg/commit/7e6031ac7427cf82cf312cb4a25040f2ePatchThird Party Advisory
- https://github.com/neocotic/convert-svg/issues/81ExploitIssue TrackingThird Party Advisory
- https://github.com/neocotic/convert-svg/pull/82PatchThird Party Advisory
- https://security.snyk.io/vuln/SNYK-JS-CONVERTSVGCORE-2849633ExploitPatchThird Party Advisory
- https://github.com/neocotic/convert-svg/commit/7e6031ac7427cf82cf312cb4a25040f2ePatchThird Party Advisory
- https://github.com/neocotic/convert-svg/issues/81ExploitIssue TrackingThird Party Advisory
- https://github.com/neocotic/convert-svg/pull/82PatchThird Party Advisory
- https://security.snyk.io/vuln/SNYK-JS-CONVERTSVGCORE-2849633ExploitPatchThird Party Advisory
FAQ
What is CVE-2022-25759?
CVE-2022-25759 is a vulnerability with a CVSS score of 9.9 (CRITICAL). The package convert-svg-core before 0.6.2 are vulnerable to Remote Code Injection via sending an SVG file containing the payload.
How severe is CVE-2022-25759?
CVE-2022-25759 has been rated CRITICAL with a CVSS base score of 9.9/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2022-25759?
Check the references section above for vendor advisories and patch information. Affected products include: Convert-Svg-Core Project Convert-Svg-Core.