VDB
Sign up
MEDIUM6.1

GHSA-45c6-75p6-83cc

fast-xml-builder Comment Value regex can be bypassed

Quick fix

GHSA-45c6-75p6-83cc — fast-xml-builder: upgrade to the fixed version with the command below.

npm install fast-xml-builder@1.1.6

Details

# Summary The fix for https://github.com/advisories/GHSA-gh4j-gqv2-49f6 in fast-xml-parser sanitizes `--` sequences in XML comment content using .replace(/--/g, '- -'). This skip the values containing three consecutive dashes (e.g., --->...), allowing an attacker to break out of an XML comment and inject arbitrary XML/HTML content.

### Impact Any application with comment property enabled allow attacker to inject malicious or unwanted code like JS script tag in the XML/HTML output.

### Workarounds Check for the presence of 3 consecutive dashes externally in the property value used for comment tag.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/fast-xml-builder
Introduced in: 1.1.5Fixed in: 1.1.6
Fixnpm install fast-xml-builder@1.1.6

References