The sitemapper project depends on fast-xml-parser@4.5.3, which contains a high-severity security vulnerability (CVE-2026-25128).
This issue allows an attacker to trigger an uncaught exception during XML parsing, potentially causing a Denial of Service (application crash).
The vulnerability was identified by Snyk and is currently rated CVSS 8.7 (High).