logo

The xmldom CDATA Flaw That Puts 23 Million Weekly Users at Risk

ID: ba5047f7-ee93-56ce-b4b5-bcb0c03558b3

STIX ID: report--ba5047f7-ee93-56ce-b4b5-bcb0c03558b3

Feed Name: securityonline.info

Threat Score
72/100

Date Published: 2026-04-02

Date Updated: 2026-04-23

Author: Ddos

...
...

A vulnerability (CVE-2026-34601, CVSS 7.5) in the xmldom JavaScript library allows attackers to inject active XML by inserting the CDATA terminator (]]>) into CDATA sections via CharacterData methods (appendData(), replaceData(), insertData()) or direct assignments (.data/.textContent). This can convert text into executable XML nodes, enabling integrity violations and downstream business-logic or privilege manipulation in systems that generate "trusted" XML (e.g., RSS, SOAP); maintainers released patches (0.8.12 and 0.9.9) and users are urged to update immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.