Skip to content

Add Socket patch for CVE-2026-25896 in pkg:npm/fast-xml-parser@5.2.5#2

Open
socket-security[bot] wants to merge 2 commits into
masterfrom
socket/autopatch-1778572127824-f32d5a2f
Open

Add Socket patch for CVE-2026-25896 in pkg:npm/fast-xml-parser@5.2.5#2
socket-security[bot] wants to merge 2 commits into
masterfrom
socket/autopatch-1778572127824-f32d5a2f

Conversation

@socket-security
Copy link
Copy Markdown

Summary

This PR updates Socket security patches for your dependencies.

Changes

  • Added: CVE-2026-25896 in pkg:npm/fast-xml-parser@5.2.5 (Socket Patch)
    • Severity: CRITICAL
    • Summary: fast-xml-parser has an entity encoding bypass via regex injection in DOCTYPE entity names

📦 Package.json Updates

This PR automatically configures your postinstall script to apply Socket patches:

  • Updated: 1 file
    • package.json

After merging, patches will automatically apply on npm install.

Testing

Review the patches and test your application to ensure compatibility.


🔒 Powered by Socket Security

socket-security Bot added 2 commits May 12, 2026 07:49
Updates:
- 6 blob(s) added
- 0 blob(s) removed
- Manifest updated
Configures package.json postinstall scripts to automatically apply Socket security patches.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants