TooTallNate / plist.js

Mac OS X Plist parser/builder for Node.js and browsers
MIT License
571 stars 123 forks source link

Request to fix the CVE-2022-37616 9.8 and CVE-2022-39353 9.8 plist #135

Closed lesley-lee closed 1 year ago

lesley-lee commented 1 year ago

Could anyone please help to fix the critical security issues CVE-2022-37616 9.8 and CVE-2022-39353, which reported a prototype pollution vulnerability exists in the function copy in dom.js in the xmldom (published as @xmldom/xmldom) package before 0.8.3 for Node.js via the p variable.

lesley-lee commented 1 year ago

Reported wrongly