A vulnerability was found in svg SVGO up to 2.8.2/3.3.3/4.0.1. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component removeScripts. Executing a manipulation can lead to cross site scripting.

This vulnerability is tracked as CVE-2026-73650. The attack can be launched remotely. No exploit exists.

It is recommended to upgrade the affected component.