VDB
Sign up
CRITICAL9.8

GHSA-wvpv-8524-wg6x

mxGraph vulnerable to XXE attacks

Quick fix

GHSA-wvpv-8524-wg6x — mxgraph: upgrade to the fixed version with the command below.

npm install mxgraph@3.7.6

Details

In `mxGraphViewImageReader.java` in mxGraph before 3.7.6, the `SAXParserFactory` instance in `convert()` is missing flags to prevent XML External Entity (XXE) attacks, as demonstrated by `/ServerView`.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/mxgraph
Introduced in: 0Fixed in: 3.7.6
Fixnpm install mxgraph@3.7.6

References