Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 30 Sep 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Satori is a library to convert HTML and CSS to SVG. Starting in version 0.0.27 and prior to version 0.33.5, Satori does not properly escape certain values before including them in generated SVG output. This can allow crafted values to be interpreted as SVG markup. The impact depends on how the generated SVG is consumed. Version 0.33.5 contains a patch. No complete workaround exists besides upgrading. Applications that cannot immediately upgrade should not render attacker-controlled content with Satori. | |
| Title | Satori-generated SVG has improper escaping | |
| Weaknesses | CWE-116 | |
| References |
|
|
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-09-30T15:48:41.962Z
Reserved: 2026-09-21T19:21:33.371Z
Link: CVE-2026-94545
No data.
Status : Received
Published: 2026-09-30T15:22:38.060
Modified: 2026-09-30T15:22:38.060
Link: CVE-2026-94545
No data.
OpenCVE Enrichment
No data.
