{"id":"GHSA-jv7g-9g6q-cxvw","summary":"Path Traversal in convert-svg packages","details":"This affects all versions of package convert-svg-core; all versions of package convert-svg-to-png; all versions of package convert-svg-to-jpeg. Using a specially crafted SVG file, an attacker could read arbitrary files from the file system and then show the file content as a converted PNG file.","aliases":["CVE-2021-23631"],"modified":"2023-11-08T04:05:12.134865Z","published":"2022-01-27T14:04:28Z","database_specific":{"github_reviewed_at":"2022-01-24T23:06:09Z","nvd_published_at":"2022-01-21T20:15:00Z","cwe_ids":["CWE-22"],"severity":"HIGH","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-23631"},{"type":"WEB","url":"https://gist.github.com/legndery/a248350bb25b8502a03c2f407cedeb14"},{"type":"PACKAGE","url":"https://github.com/neocotic/convert-svg"},{"type":"WEB","url":"https://snyk.io/vuln/SNYK-JS-CONVERTSVGCORE-1582785"},{"type":"WEB","url":"https://snyk.io/vuln/SNYK-JS-CONVERTSVGTOJPEG-2348245"},{"type":"WEB","url":"https://snyk.io/vuln/SNYK-JS-CONVERTSVGTOPNG-2348244"}],"affected":[{"package":{"name":"convert-svg-core","ecosystem":"npm","purl":"pkg:npm/convert-svg-core"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"last_affected":"0.5.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/01/GHSA-jv7g-9g6q-cxvw/GHSA-jv7g-9g6q-cxvw.json"}},{"package":{"name":"convert-svg-to-png","ecosystem":"npm","purl":"pkg:npm/convert-svg-to-png"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"last_affected":"0.5.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/01/GHSA-jv7g-9g6q-cxvw/GHSA-jv7g-9g6q-cxvw.json"}},{"package":{"name":"convert-svg-to-jpeg","ecosystem":"npm","purl":"pkg:npm/convert-svg-to-jpeg"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"last_affected":"0.5.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/01/GHSA-jv7g-9g6q-cxvw/GHSA-jv7g-9g6q-cxvw.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}