Description
xmldom versions 0.6.0 and older do not correctly escape special characters when serializing elements removed from their ancestor. This may lead to unexpected syntactic changes during XML processing in some downstream applications.
Recommendation
Update the @xmldom/xmldom package to the latest compatible version. Followings are version details:
- Affected version(s): < 0.7.0
- Patched version(s): 0.7.0
References
Could your website be exposed too?
SmartScanner can check your website for Misinterpretation of malicious XML input and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Misinterpretation of malicious XML input - xmldom - CVE-2021-32796
- Misinterpretation of malicious XML input - xmldom - GHSA-h6q6-9hqw-rwfv - CVE-2021-21366
- Improper Input Validation in sanitize-html - CVE-2021-26539
- Improper Input Validation in is-email - CVE-2021-36716


