← Back to context

Comment by p0w3n3d

7 hours ago

what exactly is the security concern with xslt?

It parses untrusted input, the library is basically unmaintained, it’s not often audited but anytime someone looks they find a CVE.

XSLT the idea contains few (but not zero) unavoidable security flaws.

libxslt the library is a barely-maintained dumpster fire of bad practices.