Misinterpretation of malicious XML input - xmldom - GHSA-h6q6-9hqw-rwfv
- Severity:
- Medium
Description
xmldom versions 0.4.0 and older do not correctly preserve system identifiers, FPIs or namespaces when repeatedly parsing and serializing maliciously crafted documents.
This may lead to unexpected syntactic changes during XML processing in some downstream applications.
Recommendation
Update the xmldom package to the latest compatible version. Followings are version details:
- Affected version(s): < 0.5.0
- Patched version(s): 0.5.0
References
Related Issues
- Misinterpretation of malicious XML input - xmldom - CVE-2021-32796
- Misinterpretation of malicious XML input - CVE-2021-32796
- xmldom has XML injection through unvalidated DocumentType serialization - CVE-2026-41674
- Improper Neutralization of Input in Theia console - CVE-2021-28161
You might also like:
- Tags:
- npm
- xmldom
Anything's wrong? Let us know Last updated on February 02, 2023


