Skip to content

Susceptible to CVE-2026-25896 (XSS in fast-xml-parser)? #1532

@bobsondugnutt2000

Description

@bobsondugnutt2000

Description

CVE-2026-25896 in the fast-xml-parser library, which is a dependency, allows XSS via regex injection. Does Graph Explorer or any of its dependencies ever parse user-provided XML via this library, or could its API be made to do so? And is it possible to bump this dependency to the patched version?


Important

If you are interested in working on this issue or have submitted
a pull request, please leave a comment.

Tip

Please use a 👍 reaction to provide a +1/vote.

This helps the community and maintainers prioritize this request.

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions