{"api_version":"v1","generated_at":"2026-10-09T13:45:00+00:00","product":{"cve_count":1,"evidence_gap_note":"Official registry publication history is linked, but a publisher support or retirement boundary has not been established.","id":"security:cve-lumi-education-ug-h5p-nodejs-library-d762eb994af8","lifecycle_state":"evidence_gap","linked_lifecycle_url":"https://lifecycle.blacktree.nl/libraries/npm/h5p-nodejs-library","name":"h5p-nodejs-library","next_cursor":null,"observations":[{"affected":"h5p-nodejs-library: < 10.0.4","affected_versions_present":true,"cve_id":"CVE-2025-7062","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-7062","fixed":"At the time of publication, no release fully prevents the upload and execution of files that contain JavaScript. Version 10.0.4 removes the SVG file extension from the default content allowlist, but it still identifies permitted files by their filename extension alone. An attacker can therefore upload a file with malicious JavaScript content under an allowed extension, such as XML, and have it executed.; Until a complete fix is available, operators should not rely on extension-based filtering alone. Uploaded files should be validated and sanitized based on their actual content rather than their filename. For SVG uploads specifically, the library's [SVG file sanitization](https://github.com/Lumieducation/H5P-Nodejs-library/blob/v10.0.4/docs/packages/h5p-svg-sanitizer.md) can be enabled, which uses DOMPurify to remove malicious script content from uploaded files.","last_modified":"2026-09-22T19:06:34.604Z","patch_url":"https://www.schutzwerk.com/en/blog/schutzwerk-sa-2024-007/","primary_source":"","published":"2026-09-09T06:14:22.143Z"}],"source_generated_at":"2026-10-09T06:17:25.511Z","vendor":"Lumi Education UG"}}
