Intel

AIKIDO-2025-10732

sitemap is vulnerable to Cross-site Scripting (XSS)

Cross-site Scripting (XSS) Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Oct 23, 2025

60

Medium Risk

This Affects:

JSsitemap
0.1.0 - 8.0.0
Fixed in 8.0.1
Are you affected? Scan for Free

TL;DR

Several vulnerabilities were found and fixed in the sitemap library. The update introduces comprehensive input validation, centralized security limits, and enhanced XML sanitization to prevent cross-site scripting via malformed attributes. It adds strict URL, numeric, and date validation to mitigate injection and denial-of-service risks, blocks protocol and path traversal attacks, and enforces limits on sitemap size and resource counts. Additional fixes include prevention of command injection in xmllint, stricter hostname and namespace validation in streams, and improvements to number and date handling across utilities.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

sitemap is vulnerable to Cross-site Scripting (XSS) in versions 0.1.0 - 8.0.0.

How to fix this

Upgrade the sitemap library to the patch version.