VDB
GCVE-110-OSM-2026-12850
GCVE-110-OSM-2026-12850
Advisory PublishedCVSS 8.8/10
The pixsvg module exports fetchDataFromSvg(svgData), which scans the input SVG for a comment of the form <!--HIDDEN_JS:([01]+)-->, reassembles the binary-encoded 1/0 sequence into a JavaScript string via binaryToData (parseInt(chunk,2) + String.fromCharCode), and passes the reconstructed string to eval(). The helper is exported on the package's public surface (module.exports.fetchDataFromSvg) but is not documented in the README and is unrelated to the advertised SVG image pipeline. Any consumer application that feeds externally-supplied SVG content through this exported function will execute attacker-controlled JavaScript in the host process. The binary-encoding-then-eval shape is a deliberate covert execution channel with no legitimate role in an image-processing library.
ENTRY
dist/browser/index.js (default-index: index.js)
EXFIL
- Data Encoding for Exfiltration in dist/commonjs/svg.js: "Buffer.from(pngBuffer).toString("base64")"
- Data Encoding for Exfiltration in dist/esm/svg.js: "Buffer.from(pngBuffer).toString("base64")"
ADDITIONAL FINDINGS
- Dynamic Code Execution in dist/commonjs/svg.js: "eval(data)"
PAYLOAD FILES
dist/commonjs/svg.js (+ dist/esm/svg.js)
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | pixsvg | all (affected) | — |
Aliases
Browse GCVE Records
3,105 records in the GCVE database · Updated October 4, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.