Improper Encoding or Escaping of Output Affecting satori package, versions >=0.0.27 <0.33.5


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

Exploit Maturity
Proof of Concept
EPSS
0.8% (55th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JS-SATORI-20360490
  • published1 Oct 2026
  • disclosed30 Sept 2026
  • creditRaghavMaheshwari124, rafabd1

Introduced: 30 Sep 2026

NewCVE-2026-94545  (opens in a new tab)
CWE-116  (opens in a new tab)

How to fix?

Upgrade satori to version 0.33.5 or higher.

Overview

satori is an Enlightened library to convert HTML and CSS to SVG.

Affected versions of this package are vulnerable to Improper Encoding or Escaping of Output in the generation of its SVG output, which places certain input values into the document without neutralizing characters that are significant in markup, so those values are parsed as SVG elements rather than as content. An attacker can inject markup of their choosing into the rendered document, by supplying a value that reaches one of the unescaped positions, such as text or an attribute drawn from user data. This requires the application to render attacker-influenced content, and the consequence depends on how the output is consumed, since an SVG embedded inline in a page is parsed in that page's origin while one referenced through an img element is not.

CVSS Base Scores

version 4.0
version 3.1