yaronn / ws.js

A WS-* client stack for node.js. Written in pure javascript!

Home Page:http://webservices20.blogspot.com/

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

SECURITY: Insecure version of xmldom

joebowbeer opened this issue · comments

The xmldom version is locked to 0.1.7 which is vulnerable to XML External Entity Injection:

https://snyk.io/test/npm/xmldom/0.1.7

@yaronn Threat-free versions of xmldom are now available at @xmldom/xmldom

https://github.com/xmldom/xmldom