CVE-2026-34601
Description
xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. In xmldom versions 0.6.0 and prior and @xmldom/xmldom prior to versions 0.8.12 and 0.9.9, xmldom/xmldom allows attacker-controlled strings containing the CDATA terminator ]]> to be inserted into a CDATASection node. During serialization, XMLSerializer emitted the CDATA content verbatim without rejecting or safely splitting the terminator. As a result, data intended to remain text-only became active XML markup in the serialized output, enabling XML structure injection and downstream business-logic manipulation. This issue has been patched in xmldom version 0.6.0 and @xmldom/xmldom versions 0.8.12 and 0.9.9.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
xmldomnpm | <= 0.6.0 | — |
@xmldom/xmldomnpm | < 0.8.12 | 0.8.12 |
@xmldom/xmldomnpm | >= 0.9.0, < 0.9.9 | 0.9.9 |
Affected products
10- osv-coords9 versionspkg:apk/chainguard/arangodb-3.11pkg:apk/chainguard/safpkg:apk/chainguard/sqlpadpkg:apk/wolfi/safpkg:apk/wolfi/sqlpadpkg:npm/%40xmldom/xmldompkg:npm/xmldompkg:rpm/opensuse/heroic-games-launcher&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/python-jupyterlab-templates&distro=openSUSE%20Tumbleweed
< 3.11.14.3-r5+ 8 more
- (no CPE)range: < 3.11.14.3-r5
- (no CPE)range: < 1.6.0-r0
- (no CPE)range: < 7.5.7-r17
- (no CPE)range: < 1.6.0-r0
- (no CPE)range: < 7.5.7-r17
- (no CPE)range: < 0.8.12
- (no CPE)range: <= 0.6.0
- (no CPE)range: < 2.20.1-5.1
- (no CPE)range: < 0.5.3-1.1
Patches
Vulnerability mechanics
References
6- github.com/advisories/GHSA-wh4c-j3r5-mjhpghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-34601ghsaADVISORY
- github.com/xmldom/xmldom/commit/2b852e836ab86dbbd6cbaf0537f584dd0b5ac184nvdWEB
- github.com/xmldom/xmldom/releases/tag/0.8.12nvdWEB
- github.com/xmldom/xmldom/releases/tag/0.9.9nvdWEB
- github.com/xmldom/xmldom/security/advisories/GHSA-wh4c-j3r5-mjhpnvdWEB
News mentions
0No linked articles in our index yet.