What is CVE-2026-73650?
CVE-2026-73650 is a vulnerability in the SVGO (SVG Optimizer) Node.js library. The `removeScripts` plugin (named `removeScriptElement` in versions 1 through 3) may leave executable content in optimized SVG files, affecting versions from 1.0.0 up to 2.8.3, 3.3.4, and 4.0.2. Users should immediately upgrade to the latest patched versions to mitigate this issue.
Azərbaycanca: CVE-2026-73650 SVGO (SVG Optimizer) Node.js kitabxanasında aşkarlanmış boşluqdur. 1.0.0 versiyasından 2.8.3, 3.3.4 və 4.0.2 versiyalarına qədər `removeScripts` (və ya 1-3 versiyalarında `removeScriptElement`) plaqini optimallaşdırılmış SVG fayllarında icra oluna bilən kod saxlayır. Bu boşluğu aradan qaldırmaq üçün təsirlənmiş versiyaları dərhal ən son yamalanmış versiyalara yeniləmək tövsiyə olunur.
FAQ2
Which versions of SVGO are affected by CVE-2026-73650?
This vulnerability affects SVGO versions starting from 1.0.0 up to 2.8.3, 3.3.4, and 4.0.2.
What measure should be taken to protect against CVE-2026-73650?
To protect against this vulnerability, it is recommended to immediately upgrade the affected SVGO versions to the latest patched versions.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.