VDB
Sign up
HIGH8.1

GHSA-mg49-jqgw-gcj6

libxmljs vulnerable to type confusion when parsing specially crafted XML

Details

libxmljs is vulnerable to a type confusion vulnerability when parsing a specially crafted XML while invoking the `namespaces()` function (which invokes `_wrap__xmlNode_nsDef_get()`) on a grand-child of a node that refers to an entity. This vulnerability can lead to denial of service and remote code execution.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/libxmljs
Introduced in: 0

No fixed version published yet for libxmljs (npm). Pin to a known-safe version or switch to an alternative.

References