Intel

AIKIDO-2026-567228

satori is vulnerable to SVG Injection

SVG InjectionCVE-2026-94545 Published 2 days ago

53

Medium Risk

This Affects:

JSsatori
0.0.27 - 0.33.4
Fixed in 0.33.5
Are you affected? Scan for Free

TL;DR

The SVG serializer in satori includes certain values in generated markup without properly escaping them. Crafted input can therefore be interpreted as SVG elements, attributes, or styles instead of text. Downstream consumers of that SVG then treat the injected markup as part of the document, so the impact depends on how the SVG is consumed. The fix hardens SVG serialization.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and your application renders attacker-controlled content with satori.

Background info

satori is vulnerable to SVG Injection in versions 0.0.27 - 0.33.4.

How to fix this

Upgrade the satori library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform