Description
xmldom versions 0.6.0 and older do not correctly escape special characters when serializing elements removed from their ancestor. This may lead to unexpected syntactic changes during XML processing in some downstream applications.
Recommendation
Update the @xmldom/xmldom package to the latest compatible version. Followings are version details:
- Affected version(s): < 0.7.0
- Patched version(s): 0.7.0
References
- GHSA-5fg8-2547-mr8q
- www.npmjs.com
- mattermost.com
- CVE-2021-32796
- CWE-116
- CAPEC-310
- OWASP 2021-A3
- OWASP 2021-A6
Related Issues
- Misinterpretation of malicious XML input - xmldom - CVE-2021-32796
- Misinterpretation of malicious XML input - xmldom - GHSA-h6q6-9hqw-rwfv - CVE-2021-21366
- Improper Input Validation in sanitize-html - CVE-2021-26539
- Improper Input Validation in is-email - CVE-2021-36716
You might also like:
- Tags:
- npm
- @xmldom/xmldom
Anything's wrong? Let us know Last updated on February 22, 2024


