Improper Input Validation in Fast XML Builder Affects Natural Intelligence Product
CVE-2026-44665

6.1MEDIUM

Key Information:

Vendor
CVE Published:
13 May 2026

What is CVE-2026-44665?

The Fast XML Builder tool, utilized for converting JSON data into XML format, contains a vulnerability that arises when processing JSON input with quotes in attribute values without enabling entity processing. This flaw can misinterpret such input, leading to the creation of multiple attributes in the XML output, allowing malicious attackers to inject unwanted attributes into the produced XML or HTML. This vulnerability has been addressed in version 1.1.7, which rectifies the improper handling of input, thus securing the data conversion process. For detailed insights, please refer to the advisory linked below.

Affected Version(s)

fast-xml-builder < 1.1.7

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.