Description
xmldom versions 0.4.0 and older do not correctly preserve system identifiers, FPIs or namespaces when repeatedly parsing and serializing maliciously crafted documents.
This may lead to unexpected syntactic changes during XML processing in some downstream applications.
Recommendation
Update the xmldom package to the latest compatible version. Followings are version details:
- Affected version(s): < 0.5.0
- Patched version(s): 0.5.0
References
Could your website be exposed too?
SmartScanner can check your website for Misinterpretation of malicious XML input - xmldom - GHSA-h6q6-9hqw-rwfv and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Misinterpretation of malicious XML input - xmldom - CVE-2021-32796
- Misinterpretation of malicious XML input - CVE-2021-32796
- xmldom has XML injection through unvalidated DocumentType serialization - CVE-2026-41674
- Improper Neutralization of Input in Theia console - CVE-2021-28161


