
Security News
Socket Releases Free Certified Patches for Critical vm2 Sandbox Escape
A critical vm2 sandbox escape can allow untrusted JavaScript to break isolation and execute commands on the host Node.js process.
@cyberhub/trust-xml2js
Advanced tools
Security Trust Report: xml2js@0.6.2 β 61/100 (C+, standard). 1 vulnerability found. Maintainer risk, supply chain analysis from 8 security databases.
xml2js@0.6.2: 61/100 | Grade: C+ | Tier: STANDARD (confidence: Β±3)
Data verified on 2026-04-02 from 8 security databases.
Maintainer Trust: ββββββββββββββββββββ 67/100
Package Health: ββββββββββββββββββββ 87/100
Supply Chain: ββββββββββββββββββββ 34/100
Community: ββββββββββββββββββββ 47/100
| Severity | Count |
|---|---|
| π΄ Critical | 1 |
Immediate:
npm update xml2js)Always: Pin version, run pkgtrust scan in CI, monitor at nrupak.com/trust/xml2js
| Package | Why | Trust Report |
|---|---|---|
| fast-xml-parser | Faster, no prototype pollution | View score |
| htmlparser2 | Streaming XML/HTML parser | View score |
Methodology: 18+ signals across 4 categories (Maintainer 35%, Package 25%, Supply Chain 25%, Community 15%). Full scoring docs β
Check your project: npm i -g @cyberhub/pkgtrust && pkgtrust scan xml2js β CLI docs
Data Sources: GitHub Advisories Β· OSV.dev Β· npm audit Β· Snyk Β· Socket.dev Β· npms.io Β· Bundlephobia Β· deps.dev
Report by pkgtrust Β· Dashboard Β· Compare Β· CLI
This is an automated security report. Not affiliated with the xml2js team. Updated 2026-04-02.
FAQs
Security Trust Report: xml2js@0.6.2 β 61/100 (C+, standard). 1 vulnerability found. Maintainer risk, supply chain analysis from 8 security databases.
We found that @cyberhub/trust-xml2js demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago.Β It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
A critical vm2 sandbox escape can allow untrusted JavaScript to break isolation and execute commands on the host Node.js process.

Research
Five malicious NuGet packages impersonate Chinese .NET libraries to deploy a stealer targeting browser credentials, crypto wallets, SSH keys, and local files.

Security News
pnpm 11 turns on a 1-day Minimum Release Age and blocks exotic subdeps by default, adding safeguards against fast-moving supply chain attacks.