CVE-2026-41674

xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) `DOMParser` and `XMLSerializer` module. In @xmldom/xmldom prior to versions 0.9.10 and 0.8.13 and xmldom version 0.6.0 and prior, the package serializes DocumentType node fields (internalSubset, publicId, systemId) verbatim without any escaping or validation. When these fields are set programmatically to attacker-controlled strings, XMLSerializer.serializeToString can produce output where the DOCTYPE declaration is terminated early and arbitrary markup appears outside it. This issue has been patched in versions @xmldom/xmldom versions 0.9.10 and 0.8.13.
CVSS

No CVSS.

Configurations

No configuration.

History

07 May 2026, 15:02

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-07 04:16

Updated : 2026-05-07 15:02


NVD link : CVE-2026-41674

Mitre link : CVE-2026-41674

CVE.ORG link : CVE-2026-41674


JSON object : View

Products Affected

No product.

CWE
CWE-91

XML Injection (aka Blind XPath Injection)