4 Total advisories
4 Vulnerabilities
0 Malware
Dependency scanning
Check whether svgo is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
HIGH 8.2
CVE-2026-73650
SVGO removeScripts plugin leaves some executable scripts intact
HIGH 7.5
CVE-2026-29074
SVGO DoS through entity expansion in DOCTYPE (Billion Laughs)
MEDIUM 6.1
CVE-2026-84369
SVGO: removeScripts incompletely sanitizes executable HTML in SVG foreignObject elements
HIGH 8.2
CVE-2026-84370
SVGO: removeScripts allows executable links through namespace and control-character bypasses
Browse more npm advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes