james-heinrich/getid3 is vulnerable to XML External Entity (XXE) Attack
30
Low Risk
Affected versions of this package enabled the LIBXML_NOENT flag when parsing XML, which instructs libxml to substitute external entities during processing. If untrusted XML input is parsed with this configuration, an attacker could exploit XML External Entity (XXE) behavior to trigger entity expansion and access sensitive local files, perform SSRF against internal services, or cause resource exhaustion through malicious entity definitions.
You are affected if you are using a version that falls within the vulnerable range.
james-heinrich/getid3 is vulnerable to XML External Entity (XXE) Attack in versions 1.9.22 - 1.9.24.
Upgrade the james-heinrich/getid3 library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant