The xmldom version is locked to 0.1.7 which is vulnerable to [XML External Entity Injection](https://snyk.io/vuln/SNYK-JS-XMLDOM-1084960): https://snyk.io/test/npm/xmldom/0.1.7