CyberRota Analysis
AI-GeneratedThe xmldom module in JavaScript versions 0.9.0 to 0.9.12 is vulnerable to XML injection due to improper validation of XML names, allowing attackers to craft malformed XML that can lead to markup injection during serialization. This vulnerability poses a high risk, as it can be exploited to manipulate XML data structures, potentially compromising application integrity. Organizations using affected versions of xmldom should prioritize upgrading to version 0.9.12 to mitigate this risk.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. From 0.9.0 until 0.9.12, the shared reg() builder in lib/grammar.js compiles the anchored QName_exact validator with the multiline flag, so ^ and $ validate only one line instead of the complete name. createElementNS, createAttributeNS, createDocumentType, and createAttribute consequently accept a malformed XML name whose first line is valid and whose later text injects markup when serialized through either the default path or requireWellFormed: true. The triggering ECMAScript line terminators are U+000A, U+000D, U+2028, and U+2029. This issue is fixed in @xmldom/xmldom version 0.9.12.