StackRadar

CVE-2026-73650

High

Advisory

Published 21 Jul 2026In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
8.2
base score, highest
EPSS
0.002
15th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
75
of 17,781 indexed, latest versions
Container images
69
deployed by those charts
Fix available
1 of 1
affected package

SVGO removeScripts plugin leaves some executable scripts intact

Carried by container images the latest versions of 75 of 17,781 indexed charts deploy, on 69 images.

Affected packageAffected versionsFixed inImages
svgonpm1.3.2, 2.8.0, 2.8.2, 3.1.0+5 more2.8.3, 3.3.4, 4.0.269
OSV records
GHSA-2p49-hgcm-8545

Charts affected

75 by stars
ChartLatestAffected imagesRadar Score
myawesomeapp-marmyawesomeapp-mar0.1.11 of 1See more

myawesomeapp-mar myawesomeapp-mar 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-73650.

Container imageDigestPackageFixed in
winfred008/amazon:910a68de5b398
svgo@2.8.0
2.8.3

Open the chart page →

2,116
myweatherhelmmyweather1.3.111 of 7See more

myweatherhelm myweather 1.3.11

1 of the 7 container images this version deploys carry CVE-2026-73650.

Container imageDigestPackageFixed in
hecrom/myweatherprocessingreactclient:1.3.115454b54d5b28
svgo@1.3.2
2.8.3

Open the chart page →

17,929
dashynas-helm-chartsVerified publisher1.0.41 of 1See more

dashy nas-helm-charts 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-73650.

Container imageDigestPackageFixed in
lissy93/dashy:2.0.51991f7be5ed0
svgo@1.3.2
2.8.3

Open the chart page →

3,269
nexus-tasksnexus-tasks2.0.01 of 5See more

nexus-tasks nexus-tasks 2.0.0

1 of the 5 container images this version deploys carry CVE-2026-73650.

Container imageDigestPackageFixed in
ghcr.io/ashvinbambhaniya/nexus-tasks-frontend:2.0.0fcbab3a24880
svgo@4.0.1
4.0.2

Open the chart page →

3,798
notes-admin-front-helm-chartnotesprojectchart0.1.01 of 1See more

notes-admin-front-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-73650.

Container imageDigestPackageFixed in
vlebediantsev/notes-admin-front:latest007c6670ff48
svgo@2.8.0
2.8.3

Open the chart page →

15,132
notes-project-fromt-helm-chartnotesprojectchart0.1.01 of 1See more

notes-project-fromt-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-73650.

Container imageDigestPackageFixed in
vlebediantsev/notes-project-front:latest945675fd2636
svgo@1.3.2
2.8.3

Open the chart page →

15,206
registration-ms-front-helm-chartnotesprojectchart0.1.01 of 1See more

registration-ms-front-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-73650.

Container imageDigestPackageFixed in
vlebediantsev/registration-ms-front-app-host:latest54f69d116c50
svgo@2.8.0
2.8.3

Open the chart page →

15,187
example-dev-toolsnoygal0.2.81 of 3See more

example-dev-tools noygal 0.2.8

1 of the 3 container images this version deploys carry CVE-2026-73650.

Container imageDigestPackageFixed in
linuxserver/codimd:latestb801bbcf6386
svgo@1.3.2
2.8.3

Open the chart page →

27,465
codimdphntom0.1.121 of 3See more

codimd phntom 0.1.12

1 of the 3 container images this version deploys carry CVE-2026-73650.

Container imageDigestPackageFixed in
phntom/codimd:2.4.31b9aafbb62e6
svgo@1.3.2
2.8.3

Open the chart page →

6,524
mastodonrivals-spaceVerified publisher3.1.21 of 3See more

mastodon rivals-space 3.1.2

1 of the 3 container images this version deploys carry CVE-2026-73650.

Container imageDigestPackageFixed in
ghcr.io/rivals-space/rivals-mastodon:1.6.143b23d55e4be
svgo@1.3.2
2.8.3

Open the chart page →

6,026
joplinrubxkubeVerified publisher1.3.11 of 2See more

joplin rubxkube 1.3.1

1 of the 2 container images this version deploys carry CVE-2026-73650.

Container imageDigestPackageFixed in
joplin/server:3.0-beta52af57880c0e
svgo@2.8.0
2.8.3

Open the chart page →

7,413
wekanschmitzis1.1.11 of 1See more

wekan schmitzis 1.1.1

1 of the 1 container images this version deploys carry CVE-2026-73650.

Container imageDigestPackageFixed in
quay.io/wekan/wekan:v5.65cb17600883a3
svgo@1.3.2
2.8.3

Open the chart page →

3,638
semaphoreschoenwald0.1.31 of 1See more

semaphore schoenwald 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-73650.

Container imageDigestPackageFixed in
0hlov3/semaphore:v1.0.050f874ec096b
svgo@2.8.0
2.8.3

Open the chart page →

1,796
secret-managersecret-managerVerified publisher1.0.01 of 4See more

secret-manager secret-manager 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-73650.

Container imageDigestPackageFixed in
leonardomulticloud/svc-vault-frontend:v1.0.0e42a341e0299
svgo@2.8.0
2.8.3

Open the chart page →

5,497
seerr-chartseerr-chartVerified publisher3.9.11 of 1See more

seerr-chart seerr-chart 3.9.1

1 of the 1 container images this version deploys carry CVE-2026-73650.

Container imageDigestPackageFixed in
ghcr.io/seerr-team/seerr:v3.4.1f4768de5f616
svgo@3.3.3
3.3.4

Open the chart page →

1,991
dashysergiotocaliniVerified publisher1.0.01 of 1See more

dashy sergiotocalini 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-73650.

Container imageDigestPackageFixed in
ghcr.io/lissy93/dashy:2.1.1acb40032ad4b
svgo@1.3.2
2.8.3

Open the chart page →

3,143
sneakerssneakers1.0.01 of 4See more

sneakers sneakers 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-73650.

Container imageDigestPackageFixed in
helga09/shoes_ukr:v1.1.17999bc8b77c0
svgo@1.3.2
2.8.3

Open the chart page →

7,574
speedtest-trackersoblivionscall3.0.41 of 1See more

speedtest-tracker soblivionscall 3.0.4

1 of the 1 container images this version deploys carry CVE-2026-73650.

Container imageDigestPackageFixed in
henrywhitaker3/speedtest-tracker:latest47159a940229
svgo@1.3.2
2.8.3

Open the chart page →

2,460
speckle-server-branch-testing5speckleVerified publisher2.21.3-branch.testing5.219631-2153bef1 of 5See more

speckle-server-branch-testing5 speckle 2.21.3-branch.testing5.219631-2153bef

1 of the 5 container images this version deploys carry CVE-2026-73650.

Container imageDigestPackageFixed in
speckle/speckle-frontend-2:2.21.3-branch.testing5.219631-2153befd4ca6ebf09b9
svgo@3.3.2
3.3.4

Open the chart page →

15,635
nordmart-reviewstakaterVerified publisher0.0.61 of 3See more

nordmart-review stakater 0.0.6

1 of the 3 container images this version deploys carry CVE-2026-73650.

Container imageDigestPackageFixed in
stakater/stakater-nordmart-review-ui:1.0.143f4926eedc74
svgo@1.3.2
2.8.3

Open the chart page →

11,554
nordmart-review-instancestakaterVerified publisher1.0.01 of 3See more

nordmart-review-instance stakater 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-73650.

Container imageDigestPackageFixed in
stakater/stakater-nordmart-review-ui:1.0.143f4926eedc74
svgo@1.3.2
2.8.3

Open the chart page →

11,554
fdi-dotstatsuite-dlmstatcan0.3.11 of 1See more

fdi-dotstatsuite-dlm statcan 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-73650.

Container imageDigestPackageFixed in
siscc/dotstatsuite-data-lifecycle-manager:v14.0.0b6f9a7c888fc
svgo@1.3.2
2.8.3

Open the chart page →

3,881
vehicle-dashboardtest-vehi-dash0.1.01 of 7See more

vehicle-dashboard test-vehi-dash 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-73650.

Container imageDigestPackageFixed in
samajh/alprfrontend:latest05ef4fddbb75
svgo@1.3.2
2.8.3

Open the chart page →

20,270
colanodevictorlane0.3.31 of 3See more

colanode victorlane 0.3.3

1 of the 3 container images this version deploys carry CVE-2026-73650.

Container imageDigestPackageFixed in
ghcr.io/colanode/server:latest7006cac874fd
svgo@2.8.2
2.8.3

Open the chart page →

2,076
sirenwateim1.0.21 of 1See more

siren wateim 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-73650.

Container imageDigestPackageFixed in
sigp/siren:v3.0.42c219b04758e
svgo@3.3.2
3.3.4

Open the chart page →

5,984

Container images carrying it

69 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/seerr-team/seerr:latest:v3.4.1f4768de5f616
svgo@3.3.3
3.3.4
3
chatwoot/chatwoot:v3.1.0d530ab8c1753
svgo@1.3.2
2.8.3
2
hoppscotch/hoppscotch:2024.8.2f1da831950b7
svgo@3.3.2
3.3.4
2
stakater/stakater-nordmart-review-ui:1.0.143f4926eedc74
svgo@1.3.2
2.8.3
2
ghcr.io/lissy93/dashy:2.1.1acb40032ad4b
svgo@1.3.2
2.8.3
2
0hlov3/semaphore:v1.0.050f874ec096b
svgo@2.8.0
2.8.3
1
apimap/developer:v1.3.1406d3858e20c
svgo@2.8.0
2.8.3
1
apimap/portal:v2.4.0041a4790c65c
svgo@2.8.0
2.8.3
1
arfath29/3-tier-app-frontend:latest384b3e377f47
svgo@1.3.2
2.8.3
1
assistiot/open_api_frontend:1.0.1f11d82defc70
svgo@1.3.2
2.8.3
1
baserow/baserow:1.30.1df0c42eb67e8
svgo@3.1.0
3.3.4
1
ccjacobs14/amazon:59a9b14a6f09e
svgo@1.3.2
2.8.3
1
chatwoot/chatwoot:v4.15.167ebc751c171
svgo@1.3.2
2.8.3
1
coderaiser/cloudcmd:16.6.1b34a9775c7ce
svgo@1.3.2
2.8.3
1
coldatom/containers-security-front:latest7c2fbbb41bcf
svgo@1.3.2
2.8.3
1
conduction/conduction-ui-app:devd591f5e6f2a9
svgo@1.3.2
2.8.3
1
directus/directus:12.0.29c8470ea465c
svgo@4.0.1
4.0.2
1
directus/directus:11.1.0e3c8bb975350
svgo@2.8.0
2.8.3
1
drumsergio/genieacs:1.2.16.028244054e1bf
svgo@3.3.3
3.3.4
1
fallenbagel/jellyseerr:latest4538137bc5af
svgo@2.8.0
2.8.3
1
fallenbagel/jellyseerr:1.7.06dcdb5ba5091
svgo@2.8.0
2.8.3
1
hecrom/myweatherprocessingreactclient:1.3.115454b54d5b28
svgo@1.3.2
2.8.3
1
helga09/shoes_ukr:v1.1.17999bc8b77c0
svgo@1.3.2
2.8.3
1
henrywhitaker3/speedtest-tracker:latest47159a940229
svgo@1.3.2
2.8.3
1
hkotel/mealie:frontend-v1.0.0beta-23c04c0e85039
svgo@1.3.2
2.8.3
1
hoppscotch/hoppscotch:2024.11.0538fe6ded4b6
svgo@3.3.2
3.3.4
1
joplin/server:3.0-beta52af57880c0e
svgo@2.8.0
2.8.3
1
joplin/server:2.14.2-betab87564ef34e9
svgo@2.8.0
2.8.3
1
kyso/kyso-front:lateste52595c5c16f
svgo@2.8.0
2.8.3
1
lavandadelpatio/frontend:latest501c3f31e0bc
svgo@1.3.2
2.8.3
1
leonardomulticloud/svc-vault-frontend:v1.0.0e42a341e0299
svgo@2.8.0
2.8.3
1
linuxserver/codimd:latestb801bbcf6386
svgo@1.3.2
2.8.3
1
linuxserver/overseerr:1.35.06108ed066d4a
svgo@2.8.0
2.8.3
1
lissy93/dashy:2.0.51991f7be5ed0
svgo@1.3.2
2.8.3
1
mautic/mautic:7-apacheeb8cc73d97e1
svgo@4.0.0
4.0.2
1
misskey/misskey:12.110.1e08b7c478093
svgo@1.3.2
2.8.3
1
mitchxxx/amazon:214e72480ec63a
svgo@2.8.0
2.8.3
1
mozilla/sentencecollector:2.0.91da6ff5c4895
svgo@1.3.2
2.8.3
1
ooghenekaro/amazon:latest03394ba1d6d8
svgo@1.3.2
2.8.3
1
phntom/codimd:2.4.31b9aafbb62e6
svgo@1.3.2
2.8.3
1
rahulbhiwagade122/desishowbiz:latest08490b70998c
svgo@3.3.2
3.3.4
1
samajh/alprfrontend:latest05ef4fddbb75
svgo@1.3.2
2.8.3
1
sigp/siren:v3.0.42c219b04758e
svgo@3.3.2
3.3.4
1
siscc/dotstatsuite-data-lifecycle-manager:v14.0.0b6f9a7c888fc
svgo@1.3.2
2.8.3
1
speckle/speckle-frontend-2:2.21.3-branch.testing5.219631-2153befd4ca6ebf09b9
svgo@3.3.2
3.3.4
1
testhubio/testhub-frontend:on-preme86c2db53be8
svgo@1.3.2
2.8.3
1
treskon/portrait-ui:DEV-lateste7970783bc8d
svgo@3.2.0
3.3.4
1
unitycatalog/unitycatalog-ui:main-aadc6fc3a688197b218
svgo@1.3.2
2.8.3
1
vabene1111/recipes:1.0.5.2ec4e9e2905b0
svgo@1.3.2
2.8.3
1
vlebediantsev/notes-admin-front:latest007c6670ff48
svgo@2.8.0
2.8.3
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.