๐Ÿ” CVE Alert

CVE-2026-44664

MEDIUM 6.1

fast-xml-builder: Comment Value bypass regex

CVSS Score
6.1
EPSS Score
0.0%
EPSS Percentile
0th

fast-xml-builder builds XML from JSON. In 1.1.5, the fix for CVE-2026-41650 in fast-xml-parser sanitizes -- sequences in XML comment content using .replace(/--/g, '- -'). This skip the values containing three consecutive dashes (e.g., --->...), allowing an attacker to break out of an XML comment and inject arbitrary XML/HTML content. This vulnerability is fixed in 1.1.6.

CWE CWE-91
Vendor naturalintelligence
Product fast-xml-builder
Published May 13, 2026
Last Updated May 13, 2026
Stay Ahead of the Next One

Get instant alerts for naturalintelligence fast-xml-builder

Be the first to know when new medium vulnerabilities affecting naturalintelligence fast-xml-builder are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None

Affected Versions

NaturalIntelligence / fast-xml-builder
1.1.5

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/NaturalIntelligence/fast-xml-builder/security/advisories/GHSA-45c6-75p6-83cc