generated from amazon-archives/__template_Apache-2.0
-
Notifications
You must be signed in to change notification settings - Fork 75
Open
Labels
bugSomething isn't workingSomething isn't working
Description
Description
CVE-2026-25896 in the fast-xml-parser library, which is a dependency, allows XSS via regex injection. Does Graph Explorer or any of its dependencies ever parse user-provided XML via this library, or could its API be made to do so? And is it possible to bump this dependency to the patched version?
Important
If you are interested in working on this issue or have submitted
a pull request, please leave a comment.
Tip
Please use a 👍 reaction to provide a +1/vote.
This helps the community and maintainers prioritize this request.
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
bugSomething isn't workingSomething isn't working