VDB
Sign up
HIGH7.5

GHSA-773h-w45w-f2f9

Denial of service vulnerability exists in libxmljs

Quick fix

GHSA-773h-w45w-f2f9 — libxmljs: upgrade to the fixed version with the command below.

npm install libxmljs@0.19.8

Details

libxmljs provides libxml bindings for v8 javascript engine. This affects all versions of package libxmljs. When invoking the libxmljs.parseXml function with a non-buffer argument the V8 code will attempt invoking the .toString method of the argument. If the argument's toString value is not a Function object V8 will crash.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/libxmljs
Introduced in: 0Fixed in: 0.19.8
Fixnpm install libxmljs@0.19.8

References