๐Ÿ” CVE Alert

CVE-2026-83607

UNKNOWN 0.0

xmldom: Element name injection via createElement() bypasses requireWellFormed

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. Prior to @xmldom/xmldom versions 0.8.14 and 0.9.11, and in xmldom version 0.6.0 and earlier, Document.createElement(tagName) stores an unvalidated element name and XMLSerializer.serializeToString() emits that name verbatim. The requireWellFormed: true path did not validate the element qualified name or synthesized xmlns:PREFIX declaration, so attacker-controlled tag names could inject attributes, elements, or processing instructions into serialized XML or HTML and could cause cross-site scripting when browser-consumed. The unchecked values violate the XML QName constraint, and default serialization and creation-time createElement() behavior remain permissive. This issue is fixed in @xmldom/xmldom versions 0.8.14 and 0.9.11; no fixed version is available for xmldom.

CWE CWE-91
Vendor xmldom
Product xmldom
Published Sep 1, 2026
Last Updated Sep 1, 2026
Stay Ahead of the Next One

Get instant alerts for xmldom xmldom

Be the first to know when new unknown vulnerabilities affecting xmldom xmldom are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

xmldom / xmldom
<= 0.6.0
@xmldom / xmldom
>= 0.7.0, < 0.8.14 >= 0.9.0, < 0.9.11

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/xmldom/xmldom/security/advisories/GHSA-w2rr-34g9-rvrj github.com: https://github.com/xmldom/xmldom/pull/1043 github.com: https://github.com/xmldom/xmldom/pull/1050 github.com: https://github.com/xmldom/xmldom/commit/cba1321218b069182695813fa7565653708e172e github.com: https://github.com/xmldom/xmldom/commit/d8212e632507eaf1d9f609657dd4c56abeb12d44 github.com: https://github.com/xmldom/xmldom/releases/tag/0.8.14 github.com: https://github.com/xmldom/xmldom/releases/tag/0.9.11