VDB

GCVE-110-OSM-2026-12850

GCVE-110-OSM-2026-12850
Advisory PublishedCVSS 8.8/10
Vulnetix · Advisory published September 30, 2026
The pixsvg module exports fetchDataFromSvg(svgData), which scans the input SVG for a comment of the form <!--HIDDEN_JS:([01]+)-->, reassembles the binary-encoded 1/0 sequence into a JavaScript string via binaryToData (parseInt(chunk,2) + String.fromCharCode), and passes the reconstructed string to eval(). The helper is exported on the package's public surface (module.exports.fetchDataFromSvg) but is not documented in the README and is unrelated to the advertised SVG image pipeline. Any consumer application that feeds externally-supplied SVG content through this exported function will execute attacker-controlled JavaScript in the host process. The binary-encoding-then-eval shape is a deliberate covert execution channel with no legitimate role in an image-processing library. ENTRY dist/browser/index.js (default-index: index.js) EXFIL - Data Encoding for Exfiltration in dist/commonjs/svg.js: "Buffer.from(pngBuffer).toString("base64")" - Data Encoding for Exfiltration in dist/esm/svg.js: "Buffer.from(pngBuffer).toString("base64")" ADDITIONAL FINDINGS - Dynamic Code Execution in dist/commonjs/svg.js: "eval(data)" PAYLOAD FILES dist/commonjs/svg.js (+ dist/esm/svg.js)

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknownpixsvgall (affected)—

References

advisory
vendor

Browse GCVE Records

3,105 records in the GCVE database · Updated October 4, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›