A pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module.
xmldom has critical vulnerabilities — do not use
Update to >= 0.9.10 to fix known vulnerabilities
| Severity | ID | Summary | Fixed in |
|---|---|---|---|
| high | CVE-2026-41673 | xmldom: Uncontrolled recursion in XML serialization leads to DoS | 0.9.10 |
| medium | CVE-2021-32796 | Misinterpretation of malicious XML input | 0.7.0 |
| critical | CVE-2022-39353 | xmldom allows multiple root nodes in a DOM | 0.9.0-beta.4 |
| high | CVE-2026-41674 | xmldom has XML injection through unvalidated DocumentType serialization | 0.9.10 |
| high | CVE-2026-41672 | xmldom has XML node injection through unvalidated comment serialization | 0.9.10 |
| high | CVE-2026-34601 | xmldom: XML injection via unsafe CDATA serialization allows attacker-controlled markup insertion | 0.9.9 |
| high | CVE-2026-41675 | xmldom has XML node injection through unvalidated processing instruction serialization | 0.9.10 |
@types/xmldom (DefinitelyTyped)Get this data programmatically — free, no authentication.
curl https://depscope.dev/api/check/npm/xmldomFirst published · 2012-01-06T09:49:36.833Z
Last updated · 2021-04-17T16:41:51.033Z