SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-84369

MEDIUM · CVSS 6.1 EPSS 0.28% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-01 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The SVGO library, specifically versions prior to 2.8.4, 3.3.5, and 4.1.0, is vulnerable due to its removeScripts plugin failing to adequately sanitize executable HTML content within SVG foreignObject elements. This oversight allows attacker-controlled SVG files to execute scripts in the viewer's context, potentially leading to data exposure and unauthorized actions. Developers and organizations utilizing SVGO for SVG optimization should prioritize upgrading to the patched versions to mitigate these risks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-84369
Severity
MEDIUM
CVSS
6.1
EPSS
0.28%

Original NVD Description

SVGO, short for SVG Optimizer, is a Node.js library and command-line application for optimizing SVG files. From version 1.0.0 until versions 2.8.4, 3.3.5, and 4.1.0, the opt-in removeScripts plugin, named removeScriptElement in versions 2 and 3 and implemented in plugins/removeScripts.js, removes SVG and XHTML script elements but does not inspect executable HTML content inside SVG foreignObject elements. Event-handler attributes such as onload and onbeforetoggle, srcdoc documents, and executable URLs in the action, data, formaction, href, and src attributes can remain in attacker-controlled SVG input. When an application uses the plugin as its only protection and serves the optimized SVG in an active browser context, the payload can execute script in the viewer's origin, expose data, modify content, or perform actions as the victim. This issue is fixed in versions 2.8.4, 3.3.5, and 4.1.0.