The package convert-svg-core before 0.6.4 are vulnerable to Directory Traversal due to improper sanitization of SVG tags. Exploiting this vulnerability is possible by using a specially crafted SVG file.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| convert-svg-core(npm) | 0 | 0.6.4 | N/A |
CVSS Metrics