CVE-2026-30117
the affected product
scalar/astro v0.1.13 was discovered to contain an arbitrary file upload vulnerability in the the scalar_url query parameter of the Scalar Proxy endpoint. This vulnerability allows attackers to execute arbitrary code via uploading a crafted SVG file.
- CVSS
- 9.8
- EPSS
- 0.53% 41.6% percentile
- CISA KEV
- Not listed
- Published
- 2026.05.20