Vulnerabilities/

xmldom has XML node injection through unvalidated comment serialization - xmldom

Severity:
High

Description

The package allows attacker-controlled comment content to be serialized into XML without validating or neutralizing comment breaking sequences. As a result, an attacker can terminate the comment early and inject arbitrary XML nodes into the serialized output.


Recommendation

No fix is available yet. Followings are affected versions:

References

Related Issues

Tags:
npm
xmldom
Anything's wrong? Let us know Last updated on May 08, 2026