XML injection in fast-xml-builder - CVE-2026-44665

 

XML injection in fast-xml-builder - CVE-2026-44665

Published: July 20, 2026


Vulnerability identifier: #VU138390
CSH Severity: Medium
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:U/U:Green
CVE-ID: CVE-2026-44665
CWE-ID: CWE-91
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: Natural Intelligence
Affected software:
fast-xml-builder

Detailed vulnerability description

The vulnerability allows a remote attacker to insert unwanted attributes to the XML/HTML.

The vulnerability exists when an input data has quotes in attribute values but process entities is not enabled, it breaks the attribute value into multiple attributes and gives the room for an attacker to insert unwanted attributes to the XML/HTML. A remote unauthenticated attacker can trick the victim into opening a specially crafted XML data to the application and perform arbitrary actions on the system.


How to mitigate CVE-2026-44665

Install updates from vendor's website.

Sources