THREAT OPS › Threat News › [GHSA] GHSA-4vpr-x523-8j87 (medium) — SVGO: removeScripts incompletely sanitizes executable HTML in SVG foreignObject elements
[GHSA] GHSA-4vpr-x523-8j87 (medium) — SVGO: removeScripts incompletely sanitizes executable HTML in SVG foreignObject elements
GHSA-4vpr-x523-8j87 Severity: medium CVE: CVE-2026-84369
SVGO: removeScripts incompletely sanitizes executable HTML in SVG foreignObject elements
## Summary
SVGO's opt-in `removeScripts` plugin did not inspect executable HTML content inside SVG `<foreignObject>` elements. Applications that used this plugin as their only protection for untrusted SVG input could produce SVGs containing active HTM
Indicators of compromise
- CVE-2026-84369cve
Original source: https://github.com/advisories/GHSA-4vpr-x523-8j87