Impact
A vulnerability has been identified in the svgdotjs svg.js library, specifically in the EventTarget.on function. Exploiting this flaw allows an attacker to manipulate object prototype attributes because the code does not properly control prototype modification. This is a prototype pollution weakness identified as CWE‑1321, with related weaknesses such as CWE‑915 and CWE‑94. The flaw can potentially enable attackers to alter application behavior, compromise data integrity, or facilitate further attacks such as remote code execution.
Affected Systems
All users of the svgdotjs svg.js library up to version 3.2.5 are affected. The vulnerability applies to the npm package for the svg.js component, which is currently unpatched. No other products or versions are listed as affected in the available data.
Risk and Exploitability
The CVSS score of 5.3 denotes a medium impact, while the EPSS lower than 1% suggests a low probability of exploitation at this time. The vulnerability is not cataloged in CISA’s KEV, implying no current evidence of exploitation in the wild. The description indicates that the attack may be initiated remotely; the likely attack vector is inferred to be remote. Because the project has not released a fix, the risk remains elevated until a proper patch or fix becomes available.
OpenCVE Enrichment