HIGH8.1
GHSA-mg49-jqgw-gcj6
libxmljs vulnerable to type confusion when parsing specially crafted XML
Details
libxmljs is vulnerable to a type confusion vulnerability when parsing a specially crafted XML while invoking the `namespaces()` function (which invokes `_wrap__xmlNode_nsDef_get()`) on a grand-child of a node that refers to an entity. This vulnerability can lead to denial of service and remote code execution.
Are you affected?
Enter the version of the package you're using.
Affected packages
npm/libxmljs
Introduced in:
0No fixed version published yet for libxmljs (npm). Pin to a known-safe version or switch to an alternative.