XML Injection Affecting anythingllm-oci-entrypoint package, versions *


Severity

Recommended
low

Based on default assessment until relevant scores are available.

Threat Intelligence

Social Trends
EPSS
0.41% (33rd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-MINIMOSLATEST-ANYTHINGLLMOCIENTRYPOINT-16325533
  • published1 May 2026
  • disclosed7 May 2026

Introduced: 1 May 2026

CVE-2026-41675  (opens in a new tab)
CWE-91  (opens in a new tab)

How to fix?

There is no fixed version for Minimos:latest anythingllm-oci-entrypoint.

NVD Description

Note: Versions mentioned in the description apply only to the upstream anythingllm-oci-entrypoint package and not the anythingllm-oci-entrypoint package as distributed by Minimos. See How to fix? for Minimos:latest relevant fixed versions and status.

xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. In @xmldom/xmldom prior to versions 0.9.10 and 0.8.13 and xmldom version 0.6.0 and prior, the package allows attacker-controlled processing instruction data to be serialized into XML without validating or neutralizing the PI-closing sequence ?>. As a result, an attacker can terminate the processing instruction early and inject arbitrary XML nodes into the serialized output. This issue has been patched in versions @xmldom/xmldom versions 0.9.10 and 0.8.13.

CVSS Base Scores

version 3.1