CVE-2026-94545
MEDIUM
5,3
Source: [email protected]
Attack Vector: network
Attack Complexity: low
Privileges Required: none
User Interaction: passive
Confidentiality: N/A
Integrity: N/A
Availability: N/A
Description
AI Translation Available
Satori is a library to convert HTML and CSS to SVG. Starting in version 0.0.27 and prior to version 0.33.5, Satori does not properly escape certain values before including them in generated SVG output. This can allow crafted values to be interpreted as SVG markup. The impact depends on how the generated SVG is consumed. Version 0.33.5 contains a patch. No complete workaround exists besides upgrading. Applications that cannot immediately upgrade should not render attacker-controlled content with Satori.
116
Improper Encoding or Escaping of Output
DraftCommon Consequences
Security Scopes Affected:
Integrity
Confidentiality
Availability
Access Control
Potential Impacts:
Modify Application Data
Execute Unauthorized Code Or Commands
Bypass Protection Mechanism
Applicable Platforms
Technologies:
Not Technology-Specific, AI/ML, Database Server, Web Server
https://github.com/vercel/next.js/commit/868fad38690d72088868f299fa2bef339b2683…
https://github.com/vercel/next.js/releases/tag/v16.3.6
https://github.com/vercel/next.js/security/advisories/GHSA-vcvr-r3jv-pc5j
https://github.com/vercel/satori/commit/26a52affc031216fee5882b6e965c8dbc7ac1782
https://github.com/vercel/satori/pull/814
https://github.com/vercel/satori/security/advisories/GHSA-wx4j-mvgx-mqwp