๐Ÿ” CVE Alert

CVE-2026-83610

UNKNOWN 0.0

xmldom: XML fragment injection via invalid EntityReference.nodeName during requireWellFormed serialization

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. Prior to @xmldom/xmldom versions 0.8.15 and 0.9.12, and in xmldom version 0.6.0 and earlier, Document.createEntityReference(name) accepts an invalid name and the ENTITY_REFERENCE_NODE serializer emits the resulting nodeName directly in &name; form. Directly serializing the node or fragment with XMLSerializer.serializeToString() and requireWellFormed: true can therefore break the entity-reference boundary and produce attacker-controlled XML markup when reparsed. The parser does not ordinarily create these nodes, and element-child insertion is rejected, so exploitation requires an application to create and directly serialize an EntityReference. This issue is fixed in @xmldom/xmldom versions 0.8.15 and 0.9.12; no fixed version is available for xmldom.

CWE CWE-116
Vendor xmldom
Product xmldom
Published Sep 1, 2026
Stay Ahead of the Next One

Get instant alerts for xmldom xmldom

Be the first to know when new unknown vulnerabilities affecting xmldom xmldom are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

xmldom / xmldom
<= 0.6.0
@xmldom / xmldom
>= 0.7.0, < 0.8.15 >= 0.9.0, < 0.9.12

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/xmldom/xmldom/security/advisories/GHSA-6gmq-8vp8-gcm6 github.com: https://github.com/xmldom/xmldom/pull/1071 github.com: https://github.com/xmldom/xmldom/pull/1072 github.com: https://github.com/xmldom/xmldom/commit/4664386e4f4d99d17b416a151dbe8323e245284b github.com: https://github.com/xmldom/xmldom/commit/6c3fb5ffeafe7901ec928ce9010988dd716c94a0 github.com: https://github.com/xmldom/xmldom/releases/tag/0.8.15 github.com: https://github.com/xmldom/xmldom/releases/tag/0.9.12