CVE-2026-41650

MEDIUM

fast-xml-parser XMLBuilder: XML Comment and CDATA Injection via Unescaped Delimiters

Title source: cna
STIX 2.1

Description

fast-xml-parser allows users to process XML from JS object without C/C++ based libraries or callbacks. Prior to version 5.7.0, XMLBuilder does not escape the "-->" sequence in comment content or the "]]>" sequence in CDATA sections when building XML from JavaScript objects. This allows XML injection when user-controlled data flows into comments or CDATA elements, leading to XSS, SOAP injection, or data manipulation. This issue has been patched in version 5.7.0.

References (2)

Core 2

Scores

CVSS v3 6.1
EPSS 0.0001
EPSS Percentile 1.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-91
Status published
Products (3)
naturalintelligence/fast-xml-parser < 5.7.0
NaturalIntelligence/fast-xml-parser < 5.7.0
npm/fast-xml-parser 0 - 5.7.0npm
Published May 07, 2026
Tracked Since May 07, 2026