Risk Scores
CVSS v3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
0.05%
17.3th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| svg | svgo | >= 2.1.0, < 2.8.1, >= 3.0.0, < 3.3.3, = 4.0.0 |
| svgo | svgo | 4.0.0, 2.1.0, 3.0.0 |
| npm | svgo | 3.0.0, 4.0.0, 4.0.0 |
Timeline
- Mar 4, 2026 CVE Published
- Mar 6, 2026 CVE Updated
- Mar 6, 2026 EPSS Score
- Mar 6, 2026 PoC Published
- Mar 6, 2026 PoC Published
- Mar 6, 2026 PoC Published
- Mar 7, 2026 EPSS Score
- Mar 8, 2026 EPSS Score
- Mar 9, 2026 EPSS Score
- Mar 9, 2026 Security Advisory
- Mar 10, 2026 EPSS Score
- Mar 11, 2026 EPSS Score
References
- https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/37405 advisory
- https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/37404 advisory
- https://github.com/svg/svgo/security/advisories/GHSA-xpqw-6gx7-v673 url
- https://nvd.nist.gov/vuln/detail/CVE-2026-29074 advisory
- https://github.com/svg/svgo package