fast-xml-parser是Natural Intelligence开源的一个库。用于在没有基于 C/C++ 的库和回调的情况下,快速验证 XML、解析 XML 和构建 XML。 fast-xml-parser 1.1.5版本存在安全漏洞,该漏洞源于修复CVE-2026-41650时对XML注释内容中--序列的清理不完整,允许攻击者跳出XML注释注入任意XML或HTML内容。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| NaturalIntelligence | fast-xml-builder | 1.1.5 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| NaturalIntelligence | fast-xml-builder | 1.1.5 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet