Summary: The svglib package through 0.9.3 for Python allows XXE attacks via an svg2rlg call.Published: Friday, March 20, 2020 - 23:15cvss: 5.0