NaturalIntelligence / fast-xml-parser

Validate XML, Parse XML and Build XML rapidly without C/C++ based libraries and no callback.
https://naturalintelligence.github.io/fast-xml-parser/
MIT License
2.54k stars 306 forks source link

Security Vulnerability report #543

Closed Sudistark closed 1 year ago

Sudistark commented 1 year ago

Hey there, I have found a security related vulnerability .

Is there any proper channel where I could forward the details ?

github-actions[bot] commented 1 year ago

I'm glad you find this repository helpful. I'll try to address your issue ASAP. You can watch the repo for new changes or star it.

amitguptagwl commented 1 year ago

Thanks for contacting. Can we connect at linkedin.

Sudistark commented 1 year ago

Just sent you the connection request, let me know how should I proceed with sharing the vuln details. And sorry for the delay didn't get any notification

amitguptagwl commented 1 year ago

Thanks a lot for highlighting the issue. It is fixed now. I would be providing another fix soon with a few more fixes.

Sudistark commented 1 year ago

Really glad to hear that, the fix pretty came out pretty fast and you have been very responsive also, great job.