SECURITY: Insecure version of xmldom
joebowbeer opened this issue · comments
Joe Bowbeer commented
The xmldom version is locked to 0.1.7 which is vulnerable to XML External Entity Injection:
Joe Bowbeer commented
@yaronn Threat-free versions of xmldom are now available at @xmldom/xmldom