Junglewise Threat Intelligence

CVE-2026-73650: SVGO removeScripts plugin incomplete XSS sanitization bypass

CVE-2026-73650 · Severity: low · CVSS 3.1 · Published 2026-07-21

Technologies: Svgo.

Executive brief

SVGO is a popular Node.js tool for optimizing SVG graphics. Its removeScripts plugin is designed to strip executable code from SVG files, but it failed to catch namespaced script tags and case-variant JavaScript URIs, leaving XSS attacks possible when used to sanitize untrusted user uploads. Applications relying on this plugin for security could serve malicious SVGs that steal cookies or session tokens from users viewing them on the same domain.

Technical details

The vulnerability is an incomplete input validation flaw (CWE-184) in SVGO's removeScripts plugin affecting versions 1.0.0–4.0.1. The plugin attempts to remove <script> elements and JavaScript URIs from SVG content but failed in two ways: (1) it did not match namespaced script tags like <svg:script> or <xhtml:script>, and (2) it performed case-sensitive matching on JavaScript URIs instead of case-insensitive matching, allowing variants like "JAVASCRIPT:" to bypass filtering. Attack requires user-supplied SVG input processed through removeScripts then served to another user on the same domain; no authentication is required. Successful exploitation leads to arbitrary JavaScript execution in the victim's browser context, enabling session hijacking and data theft. Patches are available: v2.8.3, v3.3.4, and v4.0.2. Version 1.x is deprecated and will not be patched.

Affected products

  • svg svgo 1.0.0–1.3.2, 2.0.0–2.8.2, 3.0.0–3.3.3, 4.0.0–4.0.1

Timeline

  • 2026-07-21: disclosed: GHSA-2p49-hgcm-8545 published
  • 2026-07-11: patched: v2.8.3, v3.3.4, v4.0.2 released with fixes

References