THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-w27v-7q3p-w38r (high) — SVGO: removeScripts allows executable links through namespace and control-character bypasses

[GHSA] GHSA-w27v-7q3p-w38r (high) — SVGO: removeScripts allows executable links through namespace and control-character bypasses

medgithub_advisoriesPublished 2026-09-08

GHSA-w27v-7q3p-w38r Severity: high CVE: CVE-2026-84370

SVGO: removeScripts allows executable links through namespace and control-character bypasses

## Summary

SVGO's opt-in `removeScripts` plugin failed to remove some executable links. Namespace-prefixed SVG anchors and URL schemes containing ASCII tabs or newlines could bypass its checks. Applications that used this plugin as their only protec

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-w27v-7q3p-w38r