You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
CVE-2026-25896 in the fast-xml-parser library, which is a dependency, allows XSS via regex injection. Does Graph Explorer or any of its dependencies ever parse user-provided XML via this library, or could its API be made to do so? And is it possible to bump this dependency to the patched version?
Important
If you are interested in working on this issue or have submitted
a pull request, please leave a comment.
Tip
Please use a 👍 reaction to provide a +1/vote.
This helps the community and maintainers prioritize this request.