CVE-2020-7750

CRITICAL9.6EPSS 6.2%

Cross-Site Scripting in scratch-svg-renderer

Published: 11/9/2020Modified: 3/13/2026
Also known as:GHSA-j977-g5vj-j27g

Description

This affects the package scratch-svg-renderer before 0.2.0-prerelease.20201019174008. The loadString function does not escape SVG properly, which can be used to inject arbitrary elements into the DOM via the _transformMeasurements function.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1CRITICAL9.6CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

References (3)

CVE-2020-7750 — Cross-Site Scripting in scratch-svg-renderer · VulnScope