CVE-2023-38633

Exp

A directory traversal problem in the URL decoder of librsvg before 2.56.3 could be used by local or remote attackers to disclose files (on the local filesystem outside of the expected area), as demonstrated by href=".?../../../../../../../../../../etc/passwd" in an xi:include element.

Published: 2023-07-22 Last update: 2024-11-21 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2023-38633 is rated High Exploit Risk (76.1/100): CVSS Medium severity, with high exploitation likelihood (EPSS 43.61%, 97th percentile). Core evidence: 3 public exploit reference(s) are indexed (Exploit-DB). EPSS rose +7.04% over the last day, indicating growing attacker interest. Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Public exploit references (Exploit-DB) for CVE-2023-38633

EDB-ID Source Kind Published Link
nvd_ref exploit_tag Exploit-DB ↗
nvd_ref exploit_tag Exploit-DB ↗
nvd_ref exploit_tag Exploit-DB ↗

Exploit prediction scoring system (EPSS) score for CVE-2023-38633

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2026-03-04 36.58% 43.61% +7.04%
2 2026-03-01 43.61% 36.58% -7.04%
3 2026-02-05 43.61%

Full EPSS history (47 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2023-38633

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
5.5 3.1 MEDIUM
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N Click to expand
Attack vector (AV:L)
They already need access on the box, or another person has to do something wrong; it’s not a remote drive-by.
Attack complexity (AC:L)
Once they can reach the bug, pulling it off is straightforward—no weird race conditions or rare setup.
Privileges required (PR:L)
A normal user session is enough; they don’t have to be admin.
User interaction (UI:N)
Nobody has to click “OK” or open a trap file; it can work without a victim helping.
Scope (S:U)
Damage stays in the same “trust bubble” as the broken component—no big spill into unrelated systems.
Confidentiality (C:H)
Serious risk that confidential data gets exposed in a big way.
Integrity (I:N)
Data isn’t meaningfully altered or forged.
Availability (A:N)
Service keeps running; no real outage angle.
1.8 3.6 [email protected]

Weakness enumeration for CVE-2023-38633

OS Trackers for CVE-2023-38633

vendor priority summary link
alpine CVE-2023-38633: 1 source package rows (librsvg); 10 state rows across 6 repos (3.18-community, 3.19-community, 3.20-community, 3.21-community, 3.22-community, edge-community); fixed 6, open 4. https://security.alpinelinux.org/vuln/CVE-2023-38633
debian not yet assigned CVE-2023-38633 not yet assigned priority: Debian including 1 source packages (librsvg), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. https://security-tracker.debian.org/tracker/CVE-2023-38633
gentoo normal CVE-2023-38633: 1 GLSA(s) (202408-14), 1 atom(s) (gnome-base/librsvg); latest impact normal. https://bugs.gentoo.org/buglist.cgi?quicksearch=CVE-2023-38633
redhat medium https://access.redhat.com/security/cve/CVE-2023-38633
suse high CVE-2023-38633 severity important: SUSE including 41 source package names (gdk-pixbuf-loader-rsvg, gdk-pixbuf-loader-rsvg-2.46.7-150200.3.9.1, …), 208 product×package rows across 64 product lines (Image SLES15-SP3-SAP-Azure-LI-BYOS-Production, Image SLES15-SP3-SAP-Azure-VLI-BYOS-Production, … (64 product lines)): Fixed 129, Known Not Affected 79. https://www.suse.com/security/cve/CVE-2023-38633/
ubuntu medium CVE-2023-38633 medium priority: Ubuntu including 1 source packages (librsvg), 7 status rows across 7 suites (bionic, focal, jammy, lunar, trusty, upstream, xenial): released 4, not-affected 2, ignored 1. https://ubuntu.com/security/CVE-2023-38633

Affected software / configurations for CVE-2023-38633

Vendor Product Version Raw CPE
gnome librsvg >= 2.42.3, < 2.46.6 cpe:2.3:a:gnome:librsvg:*:*:*:*:*:*:*:*
gnome librsvg >= 2.48.0, < 2.48.11 cpe:2.3:a:gnome:librsvg:*:*:*:*:*:*:*:*
gnome librsvg >= 2.50.0, < 2.50.8 cpe:2.3:a:gnome:librsvg:*:*:*:*:*:*:*:*
gnome librsvg >= 2.52.0, < 2.52.10 cpe:2.3:a:gnome:librsvg:*:*:*:*:*:*:*:*
gnome librsvg >= 2.54.0, < 2.54.6 cpe:2.3:a:gnome:librsvg:*:*:*:*:*:*:*:*
gnome librsvg >= 2.55.0, < 2.55.3 cpe:2.3:a:gnome:librsvg:*:*:*:*:*:*:*:*
gnome librsvg >= 2.56.0, < 2.56.3 cpe:2.3:a:gnome:librsvg:*:*:*:*:*:*:*:*
fedoraproject fedora 37 cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:*
fedoraproject fedora 38 cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:*
debian debian_linux 11.0 cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*
debian debian_linux 12.0 cpe:2.3:o:debian:debian_linux:12.0:*:*:*:*:*:*:*

References for CVE-2023-38633

URL Tags
http://seclists.org/fulldisclosure/2023/Jul/43 Mailing List Not Applicable Third Party Advisory
http://www.openwall.com/lists/oss-security/2023/07/27/1 Exploit Mailing List Third Party Advisory
http://www.openwall.com/lists/oss-security/2023/09/06/10 Mailing List
https://bugzilla.suse.com/show_bug.cgi?id=1213502 Issue Tracking Patch Third Party Advisory
https://gitlab.gnome.org/GNOME/librsvg/-/issues/996 Exploit Issue Tracking Vendor Advisory
https://gitlab.gnome.org/GNOME/librsvg/-/releases/2.56.3 Release Notes
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/422NTIHIEBRASIG2DWXYBH4ADYMHY626/ Third Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/R5BCXT5GW6RCL45ZUHUZR4CJG2BAFDVC/ Third Party Advisory
https://news.ycombinator.com/item?id=37415799 Issue Tracking Third Party Advisory
https://security.netapp.com/advisory/ntap-20230831-0011/ Third Party Advisory
https://www.canva.dev/blog/engineering/when-url-parsers-disagree-cve-2023-38633/ Exploit Technical Description Third Party Advisory
https://www.debian.org/security/2023/dsa-5484 Third Party Advisory
cvelogic Threat Intelligence