svgo
HighnpmCVE-2026-84370
What to do
Update svgo to 2.8.4 or later.
npm install svgo@2.8.4
A cross-site scripting flaw affects the npm package svgo. Affected versions: >= 1.0.0, < 2.8.4. Fixed from version 2.8.4. CVSS score 8.2.
What the flaw allows: Code can run in visitors’ browsers.
- Package
- svgo
- Ecosystem
- npm (JavaScript)
- Class
- Cross-site scripting
- Affected versions
- >= 1.0.0, < 2.8.4
- CVSS
- 8.2
- Published on
- September 8, 2026
Sources
Entry built automatically from the cited security advisory, with no model rewriting. Acknowledged by the organisation or vendor, notified to an authority, or established by two independent sources.