npm vulnerability intelligence

svgo NPM Package
Vulnerability Check

SVGO is a Node.js library and command-line application for optimizing vector images.

High severity MIT v4.0.1
Vulnerability Analysis OSV Live

svgo

v4.0.1 · MIT · 32,674,089 dl/wk

Advisory Breakdown

Critical 0
High 1
Moderate 0
Low 0

Severity Rating

High severity

1 advisory

High severity

Weekly downloads

32,674,089

Total advisories

1

Latest version

4.0.1

License

MIT

Known advisories

OSV records for the npm ecosystem

1
GHSA-xpqw-6gx7-v673 CVE-2026-29074 high

SVGO DoS through entity expansion in DOCTYPE (Billion Laughs)

Affected: >=2.1.0 <2.8.1, >=3.0.0 <3.3.3, >=4.0.0 <4.0.1 Fixed in: 2.8.1, 3.3.3, 4.0.1 Updated Mar 10, 2026
View source

Checked Jun 7, 2026, 5:33 PM from npm and OSV.dev

Package metadata

From the npm registry

Package name
svgo
Ecosystem
npm
Latest version
4.0.1
License
MIT
Weekly downloads
32,674,089

Remediation boundary

What RequestGuard does — and doesn't — cover

RequestGuard does not fix npm package vulnerabilities. Dependency remediation happens through package updates, patches, lockfile changes, and maintainer guidance. RequestGuard can help mitigate runtime abuse around exposed web and API flows while remediation is handled separately.

Signup flows
Login attempts
API traffic

Data from npm registry and OSV.dev · Checked 6/7/2026, 5:33:19 PM