THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-4vpr-x523-8j87 (medium) — SVGO: removeScripts incompletely sanitizes executable HTML in SVG foreignObject elements

[GHSA] GHSA-4vpr-x523-8j87 (medium) — SVGO: removeScripts incompletely sanitizes executable HTML in SVG foreignObject elements

medgithub_advisoriesPublished 2026-09-08

GHSA-4vpr-x523-8j87 Severity: medium CVE: CVE-2026-84369

SVGO: removeScripts incompletely sanitizes executable HTML in SVG foreignObject elements

## Summary

SVGO's opt-in `removeScripts` plugin did not inspect executable HTML content inside SVG `<foreignObject>` elements. Applications that used this plugin as their only protection for untrusted SVG input could produce SVGs containing active HTM

Indicators of compromise

Original source: https://github.com/advisories/GHSA-4vpr-x523-8j87