CVE-2022-25759: convert-svg-core vulnerable to remote code injection

Severity: Critical

CVSS Score: 9.8

The package convert-svg-core before 0.6.2 are vulnerable to Remote Code Injection via sending an SVG file containing the payload.