Improper Input Validation in Fast XML Builder Affects Natural Intelligence Product
CVE-2026-44665
6.1MEDIUM
What is CVE-2026-44665?
The Fast XML Builder tool, utilized for converting JSON data into XML format, contains a vulnerability that arises when processing JSON input with quotes in attribute values without enabling entity processing. This flaw can misinterpret such input, leading to the creation of multiple attributes in the XML output, allowing malicious attackers to inject unwanted attributes into the produced XML or HTML. This vulnerability has been addressed in version 1.1.7, which rectifies the improper handling of input, thus securing the data conversion process. For detailed insights, please refer to the advisory linked below.
Affected Version(s)
fast-xml-builder < 1.1.7
