XML injection in fast-xml-parser - CVE-2026-41650

 

XML injection in fast-xml-parser - CVE-2026-41650

Published: April 20, 2026


Vulnerability identifier: #VU126617
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-41650
CWE-ID: CWE-91
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to inject XML content and manipulate generated XML documents.

The vulnerability exists due to improper neutralization of special elements in XMLBuilder when building XML comments or CDATA sections from user-controlled data. A remote attacker can supply crafted comment or CDATA content containing XML delimiters to inject XML content and manipulate generated XML documents.

User interaction is required to trigger browser-side script execution in affected XML, SVG, or HTML contexts.


Affected software

fast-xml-parser

How to mitigate CVE-2026-41650

Install security update from vendor's website.

fast-xml-parser - update to 5.7.0

External References

Related Security Bulletins