Junglewise Threat Intelligence

CVE-2026-41675: xmldom XML injection in XMLSerializer processing instructions

CVE-2026-41675 · Severity: high · CVSS 7.5 · Published 2026-05-07

Technologies: Xmldom @Xmldom/Xmldom, Xmldom.

Executive brief

xmldom is a JavaScript library used to parse and create XML documents. A security flaw allows attackers to inject malicious XML content into documents generated by the library. This could lead to data corruption or the bypass of security controls that rely on the integrity of the generated XML.

Technical details

The vulnerability is classified as XML Injection (CWE-91) within the XMLSerializer component of xmldom. The root cause is the failure to validate attacker-controlled processing instruction (PI) data for the PI-closing sequence '?>' during serialization. An attacker can provide crafted input that terminates a processing instruction early, allowing the injection of arbitrary XML nodes into the serialized output. This can be exploited remotely if the application serializes user-provided data into XML. The issue is addressed in versions 0.9.10 and 0.8.13 by introducing a 'requireWellFormed' option that throws an error if injection-prone content is detected.

Affected products

  • xmldom xmldom <= 0.6.0
  • xmldom @xmldom/xmldom >= 0.9.0, < 0.9.10
  • xmldom @xmldom/xmldom < 0.8.13

Timeline

  • 2026-04-18: patched: Fixes released in versions 0.8.13 and 0.9.10
  • 2026-05-07: disclosed: Public advisory published

References