WhisperX tag archive

#attribute injection

This page collects WhisperX intelligence signals tagged #attribute injection. It is designed for humans, search engines, and AI agents: each item links to a canonical source-backed record with sector, source, timestamp, credibility, and exportable structured data.

Latest Signals (1)

The Lab · 2026-05-10 20:01:43 · GitHub Issues

1. CVE-2026-44665: Attribute Injection Flaw in fast-xml-builder Enables XSS via Malformed XML Processing

A high-severity vulnerability, CVE-2026-44665, has been identified in the fast-xml-builder npm package (versions prior to 1.1.7), exposing applications to attribute injection attacks. The flaw, detected by Trivy security scanning, stems from improper handling of quotes within XML attribute values when entity processing...