GHSA-cr9c-rhq6-vh53
Dashboard / Vulnerabilities / GHSA-cr9c-rhq6-vh53
Summary: Withdrawn: Code execution via SVG file upload in tiddlywiki
Details: ## Withdrawn Advisory This advisory has been withdrawn because it has been found to not be valid. Please see the issue [here](https://github.com/Jermolene/TiddlyWiki5/issues/7384) for more information. ## Original Description An arbitrary file upload vulnerability in the file upload module of Tiddlywiki5 v5.2.2 allows attackers to execute arbitrary code via a crafted SVG file.
References: https://nvd.nist.gov/vuln/detail/CVE-2022-29351, https://github.com/Jermolene/TiddlyWiki5/issues/7384, https://github.com/Jermolene/TiddlyWiki5, https://github.com/jimcola99/corruptsvgfile, https://www.youtube.com/watch?v=F_DBx4psWns, http://tiddlywiki5.com
Affected packages
Package
Name: tiddlywiki
Purl: pkg:npm/tiddlywiki
Affected ranges
Type: SEMVER
Events:
