CVE

CVE-2022-25759

CVE-2022-25759

The package convert-svg-core before 0.6.2 are vulnerable to Remote Code Injection via sending an SVG file containing the payload.

Source: CVE-2022-25759

Exit mobile version