Severity: Critical
CVSS Score: 9.8
The svglib package through 0.9.3 for Python allows XXE attacks via an svg2rlg call.