Description
@xmldom/xmldom allows attacker-controlled strings containing the CDATA terminator ]]> to be inserted into a CDATASection node. During serialization, XMLSerializer emitted the CDATA content verbatim without rejecting or safely splitting the terminator.
Recommendation
No fix is available yet. Followings are affected versions:
- <= 0.6.0
References
Could your website be exposed too?
SmartScanner can check your website for xmldom: XML injection via unsafe CDATA serialization allows attacker-controlled markup insertion - xmldom and gives you actionable findings to investigate.
Start a free scanRelated Issues
- xmldom: XML injection via unsafe CDATA serialization allows attacker-controlled markup insertion - CVE-2026-34601
- xmldom has XML node injection through unvalidated processing instruction serialization - xmldom - CVE-2026-41675
- xmldom has XML node injection through unvalidated comment serialization - CVE-2026-41672
- xmldom has XML node injection through unvalidated comment serialization - xmldom - CVE-2026-41672


