Affected Versions
| Affected | <= 4.5.0 |
| Fixed in | 5.7.0 (also patched in 4.5.4, 5.3.5) |
| Ecosystem | npm |
| CVE / GHSA | CVE-2026-25896 / not assigned |
| CWE | unknown |
The Vulnerability Explained
The fast-xml-parser library provides high-performance XML parsing for Node.js applications. In versions 4.5.0 and earlier, the parser's handling of DOCTYPE document type declarations contained a critical flaw: external entity references within <!ENTITY> declarations were processed without adequate sanitization, allowing attacker-controlled strings to propagate through the parsed output.
When XMLParser.parse() encounters a DOCTYPE section like:
<!DOCTYPE foo [
<!ENTITY xxe SYSTEM "file:///etc/passwd">
]>
The entity &xxe; expands during parsing. The vulnerability arises when this expansion occurs in contexts where the resulting string later reaches a browser's HTML parser without proper encoding. An attacker crafts XML where entity expansion produces a JavaScript payload:
<!DOCTYPE svg [
<!ENTITY xss "<script>alert('XSS')</script>">
]>
<svg>&xss;</svg>
If the application takes parser.parse(xml).svg and injects it into a webpage's DOM via innerHTML or similar, the script executes. The root cause is that fast-xml-parser 4.5.0 treated expanded entities as trusted content, failing to apply the contextual encoding that would prevent HTML metacharacters from becoming executable code.
Real-world impact is severe for applications that:
- Accept XML uploads from untrusted users
- Transform XML to HTML for display
- Use parsed XML values in server-side rendering templates without additional escaping
The Fix
The remediation upgrades fast-xml-parser to version 5.7.0, which contains hardened entity handling. The change appears in package.json:
- (no explicit fast-xml-parser dependency)
+ "fast-xml-parser": "5.7.0",
This explicit version pin ensures the dependency tree resolves to a patched release. The bun.lockb update propagates this constraint through the locked dependency graph.
Version 5.7.0 addresses CVE-2026-25896 by:
- Restricting external entity resolution — The parser now limits which entity types can trigger network requests or file system access
- Context-aware output encoding — Expanded entities are treated as data, not markup, when the output may reach HTML contexts
- Stricter DOCTYPE parsing — Malformed or suspicious entity declarations trigger parse errors rather than silent unsafe expansion
The upgrade path is straightforward: no API changes affect standard XMLParser usage. Applications calling new XMLParser().parse(xml) receive identical parsed structures, just without the underlying vulnerability.
Key Takeaways
-
Explicit dependency management matters: The vulnerability existed in a transitive dependency; adding an explicit
fast-xml-parserversion inpackage.jsonforces the secure version even when intermediate packages specify looser ranges. -
XML parsing requires output-context awareness: Safe parsing isn't just about the parser itself—developers must consider where parsed data flows. The same safe parser can produce vulnerable applications if output encoding is mismatched to the destination context.
-
DOCTYPE is dangerous by default: Modern XML security guidance recommends disabling DTD/DOCTYPE processing entirely when not required. The patched versions make this safer by default, but applications with strict security requirements should still explicitly set
processEntities: falsewhere the parser API permits. -
Lockfile updates are security updates: The
bun.lockbchange in this fix is as critical as thepackage.jsonchange—without regenerating the lockfile, the old vulnerable version remains installed.
How Orbis AppSec Detected This
Source: Untrusted XML input reaching XMLParser.parse() via HTTP request bodies, file uploads, or external API responses
Sink: The XMLParser constructor and parse() method in fast-xml-parser versions 4.5.0 and earlier, specifically the internal entity expansion logic triggered by DOCTYPE declarations
Missing control: Absence of version constraints preventing the vulnerable fast-xml-parser 4.5.0 from appearing in the dependency tree; no explicit disabling of entity processing through parser options
CWE: unknown (pending assignment)
Fix: Explicit dependency on fast-xml-parser 5.7.0 in package.json with corresponding lockfile regeneration to eliminate the vulnerable code path
Orbis AppSec detected this vulnerability automatically. Try Orbis AppSec on your repositories to find and fix issues like this.
Conclusion
CVE-2026-25896 demonstrates how a seemingly benign XML parsing utility can become an XSS vector through improper entity handling. The fast-xml-parser 4.5.0 vulnerability specifically exploited the trust boundary between XML entity expansion and HTML rendering contexts—an architectural concern that secure-by-default parser design must address. Upgrading to version 5.7.0 closes this gap, but the broader lesson stands: any data transformation that crosses trust boundaries requires explicit validation of both the transformation and its output encoding.