CVE-2022-21144: Libxmljs Project Libxmljs
High severity, CVSS 7.5. EPSS: 1.9% chance of exploitation in the next 30 days.
This affects all versions of package libxmljs. When invoking the libxmljs.parseXml function with a non-buffer argument the V8 code will attempt invoking the .toString method of the argument. If the argument's toString value is not a Function object V8 will crash.
Affected products
- Libxmljs Project Libxmljs: before 0.19.8 (fixed in 0.19.8)
Published 2022-05-01. Last modified 2026-06-17.