Executive brief
xmldom is a JavaScript library for parsing and manipulating XML documents. Versions 0.4.0 and older do not correctly preserve XML system identifiers and namespaces when processing maliciously crafted documents, which could lead to unexpected changes in XML content when processed by dependent applications.
Technical details
The vulnerability is a misinterpretation of malicious XML input (CWE-115, CWE-436) in xmldom's DOM parsing and serialization logic. The root cause is improper preservation of XML system identifiers (DOCTYPE declarations), FPIs (Formal Public Identifiers), and namespace declarations when repeatedly parsing and serializing specially crafted XML documents. An attacker can craft malicious XML that, when processed by xmldom and re-serialized, results in syntactic changes to the document structure. No authentication or special privileges are required; the attack requires user interaction (UI:R). The impact is limited to integrity (I:L) with no confidentiality or availability impact. The fix was released in version 0.5.0.
Affected products
- xmldom xmldom <=0.4.0
Timeline
- 2021-03-12: disclosed
- 2021-03-12: patched: Fixed in version 0.5.0