stchris/untangle

Potential vulnerability through external entities

Closed this issue · 0 comments

untangle up to version 1.2.0 is vulnerable against external entities being loaded through handcrafted malicious XML.

See https://github.com/tiran/defusedxml#attack-vectors