Skip to content

NPM Audit - xmldom vulnerability #1

@mark05e

Description

@mark05e
# npm audit report

xmldom  *
Severity: critical
xmldom allows multiple root nodes in a DOM - https://github.com/advisories/GHSA-crh6-fp67-6883
Misinterpretation of malicious XML input - https://github.com/advisories/GHSA-5fg8-2547-mr8q
No fix available
node_modules/xmldom
  cloud-text-to-speech  *
  Depends on vulnerable versions of xmldom
  node_modules/cloud-text-to-speech

2 critical severity vulnerabilities

Some issues need review, and may require choosing a different dependency.

https://github.com/xmldom/xmldom states

Since version 0.7.0 this package is published to npm as @xmldom/xmldom and no longer as xmldom, because xmldom/xmldom#271.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions