CVE-2020-10799

The svglib package through 0.9.3 for Python allows XXE attacks via an svg2rlg call.