CVE-2026-23499 | Saleor up to 3.20.107/3.21.42/3.22.26 SVG File cross site scripting (GHSA-666h-2p49-pg95 / EUVD-2026-3775)
A vulnerability labeled as problematic has been found in Saleor up to 3.20.107/3.21.42/3.22.26. This affects an unknown function of the component SVG File Handler. The manipulation results in cross site scripting.
This vulnerability is known as CVE-2026-23499. It is possible to launch the attack remotely. No exploit is available.
The affected component should be upgraded.