GHSA-45c6-75p6-83cc
fast-xml-builder Comment Value regex can be bypassed
Quick fix
GHSA-45c6-75p6-83cc — fast-xml-builder: upgrade to the fixed version with the command below.
npm install fast-xml-builder@1.1.6Details
# Summary The fix for https://github.com/advisories/GHSA-gh4j-gqv2-49f6 in fast-xml-parser sanitizes `--` sequences in XML comment content using .replace(/--/g, '- -'). This skip the values containing three consecutive dashes (e.g., --->...), allowing an attacker to break out of an XML comment and inject arbitrary XML/HTML content.
### Impact Any application with comment property enabled allow attacker to inject malicious or unwanted code like JS script tag in the XML/HTML output.
### Workarounds Check for the presence of 3 consecutive dashes externally in the property value used for comment tag.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/NaturalIntelligence/fast-xml-builder/security/advisories/GHSA-45c6-75p6-83cc[WEB]
- https://github.com/NaturalIntelligence/fast-xml-parser/security/advisories/GHSA-gh4j-gqv2-49f6[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2026-44664[ADVISORY]
- https://github.com/NaturalIntelligence/fast-xml-builder[PACKAGE]