id: PYSEC-2025-129 published: "2025-01-23T01:15:26.847Z" modified: "2025-04-15T17:13:10.040Z" aliases: - CVE-2024-57720 details: lunasvg v3.0.0 was discovered to contain a segmentation violation via the component plutovg_blend. affected: - package: name: lunasvg ecosystem: PyPI purl: pkg:pypi/lunasvg ranges: - type: ECOSYSTEM events: - introduced: "0" - last_affected: 3.0.0 - last_affected: 3.1.0 ecosystem_specific: {} references: - type: REPORT url: https://github.com/sammycage/lunasvg/issues/209 - type: EVIDENCE url: https://github.com/keepinggg/poc/blob/main/poc_of_lunasvg_3.1.0 severity: - type: CVSS_V3 score: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H