HIGH8.1
GHSA-78h3-pg4x-j8cv
libxmljs2 vulnerable to type confusion when parsing specially crafted XML
Details
libxmljs2 is vulnerable to a type confusion vulnerability when parsing a specially crafted XML while invoking the `namespaces()` function (which invokes `XmlNode::get_local_namespaces()`) on a grand-child of a node that refers to an entity. This vulnerability can lead to denial of service and remote code execution.
Are you affected?
Enter the version of the package you're using.
Affected packages
npm/libxmljs2
Introduced in:
0No fixed version published yet for libxmljs2 (npm). Pin to a known-safe version or switch to an alternative.