Input validation error in fast-xml-builder - CVE-2026-44664
Published: May 7, 2026 / Updated: July 28, 2026
fast-xml-builder
Detailed vulnerability description
The vulnerability allows a remote attacker to inject arbitrary XML or HTML content.
The vulnerability exists due to improper input validation in XML comment content sanitization when processing comment property values. A remote attacker can supply a value containing three consecutive dashes to inject arbitrary XML or HTML content.
Only applications with the comment property enabled are vulnerable.