sitemap is vulnerable to Missing XML Validation
46
Medium Risk
Affected versions of this package are vulnerable to XML injection due to incomplete entity escaping, specifically the lack of proper escaping for the > character in the text() function, and insufficient attribute name validation, which could allow an attacker to exploit this by crafting malicious inputs that bypass escaping mechanisms, leading to CDATA injection or the insertion of invalid attributes, potentially resulting in data manipulation, denial of service, or arbitrary code execution in XML-processing contexts.
You are affected if you are using a version that falls within the vulnerable range.
sitemap is vulnerable to Missing XML Validation in versions 7.1.0 - 8.0.2.
Upgrade the sitemap library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant