Skip to content

bump xmldom version by updating plist dependency#14443

Closed
bobbrow wants to merge 2 commits into
mainfrom
bobbrow/CVE-2026-41675
Closed

bump xmldom version by updating plist dependency#14443
bobbrow wants to merge 2 commits into
mainfrom
bobbrow/CVE-2026-41675

Conversation

@bobbrow
Copy link
Copy Markdown
Member

@bobbrow bobbrow commented May 11, 2026

CVE-2026-41675 wants us to update xmldom. It is only used by plist and updating that module updates the other one.

Also adding a try/catch in the code because plist.parse can throw.

@bobbrow bobbrow requested a review from a team as a code owner May 11, 2026 16:54
@github-project-automation github-project-automation Bot moved this to Pull Request in cpptools May 11, 2026
@bobbrow bobbrow marked this pull request as draft May 11, 2026 17:13
@sean-mcmanus
Copy link
Copy Markdown
Contributor

@bobbrow We're using 0.8.13 already, which has the fix.

@bobbrow bobbrow closed this May 11, 2026
@bobbrow bobbrow deleted the bobbrow/CVE-2026-41675 branch May 11, 2026 18:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: Pull Request

Development

Successfully merging this pull request may close these issues.

2 participants