sitemap is vulnerable to Cross-site Scripting (XSS)
60
Medium Risk
Several vulnerabilities were found and fixed in the sitemap library. The update introduces comprehensive input validation, centralized security limits, and enhanced XML sanitization to prevent cross-site scripting via malformed attributes. It adds strict URL, numeric, and date validation to mitigate injection and denial-of-service risks, blocks protocol and path traversal attacks, and enforces limits on sitemap size and resource counts. Additional fixes include prevention of command injection in xmllint, stricter hostname and namespace validation in streams, and improvements to number and date handling across utilities.
You are affected if you are using a version that falls within the vulnerable range.
sitemap is vulnerable to Cross-site Scripting (XSS) in versions 0.1.0 - 8.0.0.
Upgrade the sitemap library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant