Install
$ agentstack add skill-byamb4-find-cve-agent-entity-expansion ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
Entity Expansion (Billion Laughs) Detection
When to Use
Audit any package that parses XML, SVG, HTML with entity support, or YAML with alias/anchor support. This includes:
- XML/SVG parsing libraries
- Document processors (DOCX, XLSX, RSS, Atom, SOAP)
- YAML parsers with alias expansion
- Configuration file parsers
~90% CVE acceptance rate when confirmed.
Key Insight
Many parsers have NO default entity expansion limit. A 1KB XML payload with recursive entity definitions can expand to 1GB+ in memory, crashing the process with an OOM kill (uncatchable — process dies).
Entity Expansion Types
1. Billion Laughs (Internal Entity Recursion)
...
]>
&lol9;
Each level multiplies by 10. Level 9 = 10^9 = 1 billion "lol" strings.
2. Quadratic Blowup (Single Entity Repeated)
]>
&a;&a;&a;&a;&a;...&a;
Less dramatic but still effective — 50KB entity × 50000 refs = 2.5GB.
3. YAML Alias Expansion
a: &anchor
x: *anchor
y: *anchor
Recursive alias references can cause exponential expansion in some YAML parsers.
Process
Step 1: Find XML/YAML Parsing
# JavaScript
grep -rn "xml2js\|fast-xml-parser\|xmldom\|sax\|DOMParser\|cheerio" .
grep -rn "\.parseString\|\.parse(" . --include="*.js" --include="*.ts"
grep -rn "yaml\.load\|yaml\.parse\|YAML\.parse" .
# Python
grep -rn "xml\.etree\|lxml\|minidom\|xml\.sax\|defusedxml" .
grep -rn "yaml\.load\|yaml\.safe_load\|yaml\.unsafe_load" .
# Go
grep -rn "xml\.Decoder\|xml\.Unmarshal\|encoding/xml" .
grep -rn "yaml\.Unmarshal\|gopkg.in/yaml" .
# Ruby
grep -rn "Nokogiri\|REXML\|Ox\.\|LibXML" .
# PHP
grep -rn "simplexml\|DOMDocument\|XMLReader\|xml_parse" .
Step 2: Check Entity/DTD Configuration
For each parser found, check:
- Does it process DTD declarations by default?
- Is there a
maxExpansionormaxEntitySizeoption? - Is DTD processing explicitly disabled?
- Does it support custom entity resolution?
Step 3: Check for Expansion Limits
grep -rn "maxExpansion\|maxEntitySize\|entityExpansion\|ENTITY_EXPANSION" .
grep -rn "disableDTD\|forbidDTD\|dtd.*false\|FEATURE_SECURE_PROCESSING" .
grep -rn "noent\|resolve_entities\|processEntities" .
Step 4: Check YAML Alias Limits
grep -rn "maxAliasCount\|maxAliases\|aliasLimit\|MAX_ALIAS" .
grep -rn "anchorLimit\|maxAnchors" .
Step 5: Verify Exploitability
- Does the parser accept untrusted input? (user uploads, API requests, webhook payloads)
- Is there a file size limit that would prevent the payload from being processed?
- Is the process memory-limited (cgroups, ulimit)?
- Does the parser use streaming that could limit memory usage?
Known Parser Default Safety
| Parser | Language | DTD/Entity Default | Safe? | |--------|----------|-------------------|-------| | fast-xml-parser | JS | Entities processed, no limit | UNSAFE | | xml2js | JS | Entities processed, no limit | UNSAFE | | xmldom | JS | Entities processed, no limit | UNSAFE | | sax | JS | No entity expansion | SAFE | | cheerio (htmlparser2) | JS | No DTD support | SAFE | | xml.etree.ElementTree | Python | Entities processed, no limit | UNSAFE | | lxml | Python | DTD disabled by default | SAFE (default) | | defusedxml | Python | All dangerous features disabled | SAFE | | xml.sax | Python | Entities processed | UNSAFE | | PyYAML yaml.load | Python | Aliases processed, no limit | UNSAFE | | PyYAML yaml.safeload | Python | Aliases processed, no limit | UNSAFE (aliases) | | encoding/xml | Go | No entity support | SAFE | | go-yaml v3 | Go | Aliases processed, limited | CHECK VERSION | | Nokogiri | Ruby | DTD disabled by default | SAFE (default) | | REXML | Ruby | Entities processed | UNSAFE | | simplexmlload_string | PHP | Entities processed by default | UNSAFE | | DOMDocument | PHP | Entities processed by default | UNSAFE |
CVSS Guidance
- Unauthenticated OOM crash (process dies): HIGH 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
- Authenticated OOM crash: MEDIUM 6.5 (PR:L)
- CPU exhaustion (recoverable): MEDIUM 5.3
References
- [Sinks](references/sinks.md) — XML/YAML parser safety status by language
- [False Positive Indicators](references/false-positive-indicators.md) — When this isn't exploitable
- [PoC Skeleton](references/poc-skeleton.md) — Billion Laughs payload templates
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: ByamB4
- Source: ByamB4/find-cve-agent
- License: Apache-2.0
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.