Vulnerabilities/

xmldom has XML node injection through unvalidated processing instruction serialization

Severity:
High

Description

The package allows attacker-controlled processing instruction data to be serialized into XML without validating or neutralizing the PI-closing sequence ?>. As a result, an attacker can terminate the processing instruction early and inject arbitrary XML nodes into the serialized output.


Recommendation

Update the @xmldom/xmldom package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@xmldom/xmldom
Anything's wrong? Let us know Last updated on May 08, 2026