Xml digital signature and encryption library for Node.js
83%
Total Score
65
100
100
100
50
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2025-10229 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. xml-crypto is vulnerable to Incorrect Authorization in versions 4.0.0 - 6.0.1. | 4.0.0 - 6.0.1 | High |
CVE-2025-29774 xml-crypto is vulnerable to Improper Verification of Cryptographic Signature in versions 4.0.0 - 6.0.1, 3.0.0 - 3.2.1 and 0.0.0 - 2.1.6. | 0.0.0 - 2.1.63.0.0 - 3.2.14.0.0 - 6.0.1 | Critical |
CVE-2025-29775 xml-crypto is vulnerable to Improper Verification of Cryptographic Signature in versions 4.0.0 - 6.0.1, 3.0.0 - 3.2.1 and 0.0.0 - 2.1.6. | 0.0.0 - 2.1.63.0.0 - 3.2.14.0.0 - 6.0.1 | Critical |
CVE-2024-32962 xml-crypto is vulnerable to Improper Verification of Cryptographic Signature in versions 4.0.0 - 6.0.0. | 4.0.0 - 6.0.0 | Critical |
| Dependency | Last Release | Score |
|---|---|---|
xpath Version ^0.0.33 | — | — |
@xmldom/xmldom Version ^0.8.10 | — | — |
@xmldom/is-dom-node Version ^1.0.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant