Skip to content

[Security] Update dependency fast-xml-parser to v5.x to address critical finding #213

@abd-hazeke

Description

@abd-hazeke

A vulnerability was recently identified in the fast-xml-parser package, which is currently a dependency (or sub-dependency) of eslint-plugin-lwc. We use this plugin within the Salesforce Code Analyzer for scanning LWC/JS components, and this CVE is now appearing in our security audits.

Link for cve: https://nvd.nist.gov/vuln/detail/CVE-2026-25128

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions