SVGO is a Node.js library and command-line application for optimizing vector images.
97%
Total Score
100
81
100
100
100
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-858273 New svgo is vulnerable to Cross-Site Scripting (XSS) in versions 1.0.0 - 2.8.3, 3.0.0 - 3.3.4 and 4.0.0 - 4.0.2. | 1.0.0 - 2.8.33.0.0 - 3.3.44.0.0 - 4.0.2 | High |
AIKIDO-2026-676071 New svgo is vulnerable to Cross-Site Scripting (XSS) in versions 1.0.0 - 2.8.3, 3.0.0 - 3.3.4 and 4.0.0 - 4.0.2. | 1.0.0 - 2.8.33.0.0 - 3.3.44.0.0 - 4.0.2 | Medium |
CVE-2026-73650 svgo is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 1.0.0 - 2.8.3, 3.0.0 - 3.3.4 and 4.0.0 - 4.0.2. | 1.0.0 - 2.8.33.0.0 - 3.3.44.0.0 - 4.0.2 | High |
CVE-2026-29074 svgo is vulnerable to Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion') in versions 2.1.0 - 2.8.1, 3.0.0 - 3.3.3 and 4.0.0 - 4.0.0. | 2.1.0 - 2.8.13.0.0 - 3.3.34.0.0 - 4.0.0 | High |
| Dependency | Last Release | Score |
|---|---|---|
sax Version 1.6.1 | — | — |
csso Version ^5.0.5 | — | — |
css-tree Version ^3.0.1 | — | — |
css-what Version ^7.0.0 | — | — |
commander Version ^11.1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant