CVE-2026-84369 | svg SVGO up to 2.8.3/3.3.4/4.0.x removeScripts plugins/removeScripts.js cross site scripting
A vulnerability described as problematic has been identified in svg SVGO up to 2.8.3/3.3.4/4.0.x. Impacted is an unknown function of the file plugins/removeScripts.js of the component removeScripts. Executing a manipulation can lead to cross site scripting.
The identification of this vulnerability is CVE-2026-84369. The attack may be launched remotely. There is no exploit available.
Upgrading the affected component is recommended.VulDB Recent EntriesRead More