VYPR
Critical severity9.8NVD Advisory· Published Oct 11, 2022· Updated Jun 17, 2026

CVE-2022-37616

CVE-2022-37616

Description

A prototype pollution vulnerability exists in the function copy in dom.js in the xmldom (published as @xmldom/xmldom) package before 0.8.3 for Node.js via the p variable. NOTE: the vendor states "we are in the process of marking this report as invalid"; however, some third parties takes the position that "A prototype injection/Prototype pollution is not just when global objects are polluted with recursive merge or deep cloning but also when a target object is polluted."

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
@xmldom/xmldomnpm
>= 0.8.0, < 0.8.30.8.3
xmldomnpm
<= 0.6.0
@xmldom/xmldomnpm
>= 0.9.0-beta.1, < 0.9.0-beta.20.9.0-beta.2
@xmldom/xmldomnpm
< 0.7.60.7.6

Affected products

6
  • Xmldom/Xmldomcpe-rescue
  • cpe:2.3:a:xmldom_project:xmldom:*:*:*:*:*:node.js:*:*+ 1 more
    • cpe:2.3:a:xmldom_project:xmldom:*:*:*:*:*:node.js:*:*range: <=0.6.0
    • cpe:2.3:a:xmldom_project:xmldom:0.9.0:beta1:*:*:*:node.js:*:*
  • cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
  • ghsa-coords2 versions
    >= 0.8.0, < 0.8.3+ 1 more
    • (no CPE)range: >= 0.8.0, < 0.8.3
    • (no CPE)range: <= 0.6.0

Patches

Vulnerability mechanics

References

14

News mentions

0

No linked articles in our index yet.