SVGO is a Node.js library and command-line application for optimizing vector images.
78%
Total Score
49
100
100
90
50
| Title | Versions | Severity |
|---|---|---|
CVE-2026-29074 svgo is vulnerable to Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion') in versions 2.1.0 - 2.8.1, 3.0.0 - 3.3.3 and 4.0.0 - 4.0.0. | 2.1.0 - 2.8.13.0.0 - 3.3.34.0.0 - 4.0.0 | High |
| Dependency | Last Release | Score |
|---|---|---|
sax Version ^1.5.0 | — | — |
csso Version ^5.0.5 | — | — |
css-tree Version ^3.0.1 | — | — |
css-what Version ^6.1.0 | — | — |
commander Version ^11.1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant