safe-svg vulnerabilities
CVEs whose affected-version data names the safe-svg package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-94077Medium· 6.5Contributor Cross Site Scripting (XSS) in Safe SVG <= 2.5.0 versions.
Contributor Cross Site Scripting (XSS) in Safe SVG <= 2.5.0 versions.
▾ Sunlit10up · safe-svgvia NVD
CVE-2026-94672Medium· 4.3Contributor Insecure Direct Object References (IDOR) in Safe SVG <= 2.5.0 versions.
Contributor Insecure Direct Object References (IDOR) in Safe SVG <= 2.5.0 versions.
▾ Sunlit10up · safe-svgvia NVD