๐Ÿ” CVE Alert

CVE-2026-83605

UNKNOWN 0.0

xmldom: Attribute name injection via setAttribute() bypasses requireWellFormed

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. Prior to @xmldom/xmldom versions 0.8.14 and 0.9.11, and in xmldom version 0.6.0 and earlier, Element.setAttribute() calls the private _createAttribute(name) path without validating the attribute name, while Document.createAttribute(name) validates against QName. XMLSerializer.serializeToString() emits attribute names verbatim, and requireWellFormed: true did not validate them, so a crafted name can terminate the intended attribute and inject additional attributes, including event handlers, into browser-consumed output; synthesized xmlns:PREFIX declarations expose the same unchecked-name boundary. This issue is fixed in @xmldom/xmldom versions 0.8.14 and 0.9.11; no fixed version is available for xmldom.

CWE CWE-91
Vendor xmldom
Product xmldom
Published Sep 1, 2026
Stay Ahead of the Next One

Get instant alerts for xmldom xmldom

Be the first to know when new unknown vulnerabilities affecting xmldom xmldom are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

xmldom / xmldom
<= 0.6.0
@xmldom / xmldom
>= 0.7.0, < 0.8.14 >= 0.9.0, < 0.9.11

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/xmldom/xmldom/security/advisories/GHSA-4w3w-2rp5-g8jm github.com: https://github.com/xmldom/xmldom/pull/1043 github.com: https://github.com/xmldom/xmldom/pull/1050 github.com: https://github.com/xmldom/xmldom/commit/cba1321218b069182695813fa7565653708e172e github.com: https://github.com/xmldom/xmldom/commit/d8212e632507eaf1d9f609657dd4c56abeb12d44 github.com: https://github.com/xmldom/xmldom/releases/tag/0.8.14 github.com: https://github.com/xmldom/xmldom/releases/tag/0.9.11