Critical severity9.8NVD Advisory· Published Oct 11, 2022· Updated Jun 17, 2026
CVE-2022-37616
CVE-2022-37616
Description
A prototype pollution vulnerability exists in the function copy in dom.js in the xmldom (published as @xmldom/xmldom) package before 0.8.3 for Node.js via the p variable. NOTE: the vendor states "we are in the process of marking this report as invalid"; however, some third parties takes the position that "A prototype injection/Prototype pollution is not just when global objects are polluted with recursive merge or deep cloning but also when a target object is polluted."
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
@xmldom/xmldomnpm | >= 0.8.0, < 0.8.3 | 0.8.3 |
xmldomnpm | <= 0.6.0 | — |
@xmldom/xmldomnpm | >= 0.9.0-beta.1, < 0.9.0-beta.2 | 0.9.0-beta.2 |
@xmldom/xmldomnpm | < 0.7.6 | 0.7.6 |
Affected products
6cpe:2.3:a:xmldom_project:xmldom:*:*:*:*:*:node.js:*:*+ 1 more
- cpe:2.3:a:xmldom_project:xmldom:*:*:*:*:*:node.js:*:*range: <=0.6.0
- cpe:2.3:a:xmldom_project:xmldom:0.9.0:beta1:*:*:*:node.js:*:*
- ghsa-coords2 versions
>= 0.8.0, < 0.8.3+ 1 more
- (no CPE)range: >= 0.8.0, < 0.8.3
- (no CPE)range: <= 0.6.0
Patches
Vulnerability mechanics
References
14- github.com/xmldom/xmldom/blob/bc36efddf9948aba15618f85dc1addfc2ac9d7b2/lib/dom.jsnvdPatchThird Party AdvisoryWEB
- github.com/xmldom/xmldom/blob/bc36efddf9948aba15618f85dc1addfc2ac9d7b2/lib/dom.jsnvdPatchThird Party AdvisoryWEB
- github.com/xmldom/xmldom/issues/436nvdIssue TrackingPatchThird Party AdvisoryWEB
- users.encs.concordia.ca/~mmannan/publications/JS-vulnerability-aisaccs2022.pdfnvdTechnical DescriptionThird Party AdvisoryWEB
- dl.acm.org/doi/abs/10.1145/3488932.3497769nvdTechnical DescriptionThird Party AdvisoryWEB
- dl.acm.org/doi/pdf/10.1145/3488932.3497769nvdThird Party AdvisoryWEB
- github.com/advisories/GHSA-9pgh-qqpf-7wqjghsaADVISORY
- github.com/xmldom/xmldom/issues/436nvdIssue TrackingThird Party AdvisoryWEB
- github.com/xmldom/xmldom/issues/436nvdIssue TrackingThird Party AdvisoryWEB
- github.com/xmldom/xmldom/security/advisories/GHSA-9pgh-qqpf-7wqjnvdThird Party AdvisoryWEB
- lists.debian.org/debian-lts-announce/2022/10/msg00023.htmlnvdMailing ListThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2022-37616ghsaADVISORY
- github.com/xmldom/xmldom/blob/master/CHANGELOG.mdghsaWEB
- github.com/xmldom/xmldom/pull/437ghsaWEB
News mentions
0No linked articles in our index yet.