CVE-2023-26107EPSS p33.3%

CVE-2023-26107CVE-2023-26107

ebay / sketchsvg

Description

All versions of the package sketchsvg are vulnerable to Arbitrary Code Injection when invoking shell.exec without sanitization nor parametrization while concatenating the current directory as part of the command string.

Scoring

CVSS 6.9 ()
VectorCVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L
EPSS0.40% probability of exploitation · percentile 33.3% · 2026-08-03T12:00:16Z
Last modified2026-06-17
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.