CVE-2024-34345: Cyclonedx Cyclonedx-JavaScript-Library
High severity, CVSS 8.1. EPSS: 0.9% chance of exploitation in the next 30 days.
The CycloneDX JavaScript library contains the core functionality of OWASP CycloneDX for JavaScript. In 6.7.0, XML External entity injections were possible, when running the provided XML Validator on arbitrary input. This issue was fixed in version 6.7.1.
Affected products
- Cyclonedx Cyclonedx-JavaScript-Library: version 6.7.0 only
Published 2024-05-14. Last modified 2026-06-17.