Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

libxmljs2 RCE security issue #2469

Closed
frigioiustefan opened this issue Nov 23, 2024 · 2 comments · Fixed by #2604
Closed

libxmljs2 RCE security issue #2469

frigioiustefan opened this issue Nov 23, 2024 · 2 comments · Fixed by #2604
Assignees
Labels
bug Something isn't working

Comments

@frigioiustefan
Copy link

Describe your issue

epg depends on libxmljs2 which has a security vulnerability as outlined in GHSA-78h3-pg4x-j8cv and this repo is no longer maintained. Doesn't it present a worrying risk for this project?

@frigioiustefan frigioiustefan added the bug Something isn't working label Nov 23, 2024
@freearhey
Copy link
Collaborator

Doesn't it present a worrying risk for this project?

I honestly don't know, but if someone knows a good alternative and is ready to rewrite codebase for it, welcome!

@hurzl
Copy link

hurzl commented Jan 15, 2025

Now with nodejs 23 it breaks compilation (#2593)
alternative? CycloneDX/cyclonedx-javascript-library#1079 (comment)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working
Development

Successfully merging a pull request may close this issue.

3 participants