CyberRota Analysis
AI-GeneratedThe vulnerability affects the xmldom library, specifically versions prior to 0.8.14 and 0.9.11, as well as xmldom version 0.6.0 and earlier. It allows for the injection of additional attributes, including event handlers, due to a lack of validation in the Element.setAttribute() method, which can lead to potential security risks such as cross-site scripting (XSS) when processed by browsers. Developers and organizations using affected versions of the xmldom library should prioritize updating to the fixed versions to mitigate these risks.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. Prior to @xmldom/xmldom versions 0.8.14 and 0.9.11, and in xmldom version 0.6.0 and earlier, Element.setAttribute() calls the private _createAttribute(name) path without validating the attribute name, while Document.createAttribute(name) validates against QName. XMLSerializer.serializeToString() emits attribute names verbatim, and requireWellFormed: true did not validate them, so a crafted name can terminate the intended attribute and inject additional attributes, including event handlers, into browser-consumed output; synthesized xmlns:PREFIX declarations expose the same unchecked-name boundary. This issue is fixed in @xmldom/xmldom versions 0.8.14 and 0.9.11; no fixed version is available for xmldom.