Vulnerabilities/

mxGraph vulnerable to XXE attacks

Severity:
High

Description

In mxGraphViewImageReader.java in mxGraph before 3.7.6, the SAXParserFactory instance in convert() is missing flags to prevent XML External Entity (XXE) attacks, as demonstrated by /ServerView.

Recommendation

Update the mxgraph package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
mxgraph
Anything's wrong? Let us know Last updated on October 19, 2023