THREAT OPS › Threat News › [GHSA] GHSA-w27v-7q3p-w38r (high) — SVGO: removeScripts allows executable links through namespace and control-character bypasses
[GHSA] GHSA-w27v-7q3p-w38r (high) — SVGO: removeScripts allows executable links through namespace and control-character bypasses
GHSA-w27v-7q3p-w38r Severity: high CVE: CVE-2026-84370
SVGO: removeScripts allows executable links through namespace and control-character bypasses
## Summary
SVGO's opt-in `removeScripts` plugin failed to remove some executable links. Namespace-prefixed SVG anchors and URL schemes containing ASCII tabs or newlines could bypass its checks. Applications that used this plugin as their only protec
MITRE ATT&CK techniques
- JavaScriptT1059.007
Indicators of compromise
- CVE-2026-84370cve
Original source: https://github.com/advisories/GHSA-w27v-7q3p-w38r