Description
svg2png 4.1.1 allows XSS with resultant SSRF via JavaScript inside an SVG document.
Remediation
References
https://github.com/domenic/svg2png/issues/117
Related Vulnerabilities
CVE-2021-3666 Vulnerability in npm package body-parser-xml
CVE-2022-1295 Vulnerability in maven package org.webjars.bower:fullpage.js
CVE-2020-28495 Vulnerability in npm package total.js
CVE-2023-26479 Vulnerability in maven package org.xwiki.platform:xwiki-platform-rendering-parser
CVE-2020-7683 Vulnerability in npm package rollup-plugin-server