Description
xmldom versions 0.6.0 and older do not correctly escape special characters when serializing elements removed from their ancestor. This may lead to unexpected syntactic changes during XML processing in some downstream applications.
Recommendation
No fix is available yet. Followings are affected versions:
- <= 0.6.0
References
- GHSA-5fg8-2547-mr8q
- www.npmjs.com
- mattermost.com
- CVE-2021-32796
- CWE-116
- CAPEC-310
- OWASP 2021-A3
- OWASP 2021-A6
Related Issues
- Misinterpretation of malicious XML input - CVE-2021-32796
- Misinterpretation of malicious XML input - xmldom - GHSA-h6q6-9hqw-rwfv - CVE-2021-21366
- Improper Input Validation in sanitize-html - sanitize-html - CVE-2021-26540
- @babel/plugin-transform-modules-systemjs generates arbitrary code when compiling malicious input - CVE-2026-44728
You might also like:
- Tags:
- npm
- xmldom
Anything's wrong? Let us know Last updated on February 22, 2024


