Cross-site scripting in Kiwi - CVE-2023-27489
Published: March 29, 2023 / Updated: September 18, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary code in a victim's browser.
The vulnerability exists due to improper neutralization of input during web page generation in SVG file upload handling when rendering an uploaded SVG file. A remote user can upload a crafted SVG file to execute arbitrary code in a victim's browser.
User interaction is required to view the uploaded SVG file.