Skip to content

NPM Audit - xmldom vulnerability #1

Description

@mark05e
# npm audit report

xmldom  *
Severity: critical
xmldom allows multiple root nodes in a DOM - https://github.com/advisories/GHSA-crh6-fp67-6883
Misinterpretation of malicious XML input - https://github.com/advisories/GHSA-5fg8-2547-mr8q
No fix available
node_modules/xmldom
  cloud-text-to-speech  *
  Depends on vulnerable versions of xmldom
  node_modules/cloud-text-to-speech

2 critical severity vulnerabilities

Some issues need review, and may require choosing a different dependency.

https://github.com/xmldom/xmldom states

Since version 0.7.0 this package is published to npm as @xmldom/xmldom and no longer as xmldom, because xmldom/xmldom#271.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions