The xmldom CDATA Flaw That Puts 23 Million Weekly Users at Risk
ID: ba5047f7-ee93-56ce-b4b5-bcb0c03558b3
STIX ID: report--ba5047f7-ee93-56ce-b4b5-bcb0c03558b3
Feed Name: securityonline.info
A vulnerability (CVE-2026-34601, CVSS 7.5) in the xmldom JavaScript library allows attackers to inject active XML by inserting the CDATA terminator (]]>) into CDATA sections via CharacterData methods (appendData(), replaceData(), insertData()) or direct assignments (.data/.textContent). This can convert text into executable XML nodes, enabling integrity violations and downstream business-logic or privilege manipulation in systems that generate "trusted" XML (e.g., RSS, SOAP); maintainers released patches (0.8.12 and 0.9.9) and users are urged to update immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
