Description
xmldom versions 0.6.0 and older do not correctly escape special characters when serializing elements removed from their ancestor. This may lead to unexpected syntactic changes during XML processing in some downstream applications.
Recommendation
No fix is available yet. Followings are affected versions:
- <= 0.6.0
References
Could your website be exposed too?
SmartScanner can check your website for Misinterpretation of malicious XML input - xmldom and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Misinterpretation of malicious XML input - CVE-2021-32796
- Misinterpretation of malicious XML input - xmldom - GHSA-h6q6-9hqw-rwfv - CVE-2021-21366
- Improper Input Validation in sanitize-html - sanitize-html - CVE-2021-26540
- @babel/plugin-transform-modules-systemjs generates arbitrary code when compiling malicious input - CVE-2026-44728


