CVE-2026-34601Disclosure

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) `DOMParser` and `XMLSerializer` module. In xmldom versions 0.6.0 and prior and @xmldom/xmldom prior to versions 0.8.12 and 0.9.9, xmldom/xmldom allows attacker-controlled strings containing the CDATA terminator ]]> to be inserted into a CDATASection node. During serialization, XMLSerializer emitted the CDATA content verbatim without rejecting or safely splitting the terminator. As a result, data intended to remain text-only became active XML markup in the serialized output, enabling XML structure injection and downstream business-logic manipulation. This issue has been patched in xmldom version 0.6.0 and @xmldom/xmldom versions 0.8.12 and 0.9.9.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-91

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 3d ago at 1 mentions (2026-04-01); latest day: 1
  • 4 total mentions across 4 days

Deep dive

Activity timeline4 mentions / 4d
00111Mentions · 2026-04-01: 1Mentions · 2026-04-02: 1Mentions · 2026-04-09: 1Mentions · 2026-07-29: 1Patch / Workaround · 2026-04-01: 1Patch / Workaround · 2026-04-02: 1Technical Details · 2026-04-01: 1Technical Details · 2026-04-02: 1Technical Details · 2026-04-09: 104-0104-0204-0907-29
Signal classification2 categories
Disclosure
375.0%
Patch
125.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-04-011
Disclosure1
2026-04-021
Patch1
2026-04-091
Disclosure1
2026-07-291
Disclosure1
Full discourse4 posts
  • Gray Hats@the_yellow_fall
    Patch

    Fix CVE-2026-34601 in @xmldom/xmldom (CVSS 7.5). A CDATA injection flaw allows attackers to bypass "safe zones" and manipulate business logic. Update now! #xmldom #XMLInjection #CyberSecurity #InfoSec #JavaScript #NodeJS #Vulnerability #PatchAlert #AppSec https://securityonline.info/xmldom-xml-injection-vulnerability-cve-2026-34601/ https://t.co/YnDswnXEdb

    Post summary

    The post announces the discovery of CVE‑2026‑34601, a CDATA injection flaw with a CVSS score of 7.5, and urges users of @xmldom/xmldom to update immediately to apply the patch.

    02021260
    11.0K followersView on X
  • Ali shmery@Alishmery2
    Disclosure

    By the grace of God I’m sharing CVE-2026-34601 from my research in xmldom now listed by ENISA as EUVD-2026-18460 The flaw survived for 14+ years in a package with ~40M weekly downloads and triggered fixes across major software supply chains #CVE #Cybersecurity

    Post summary

    The tweet announces the discovery and sharing of CVE‑2026‑34601 in xmldom, highlighting its long persistence and supply‑chain impact, but offers no technical details, PoC, or patch information.

    0001029
    13 followersView on X
  • White Rabbitx 🏴‍☠️@TheRabbitPy
    Disclosure

    💥 CVE-2026-34601 (xmldom): High XML injection via unsafe CDATA serialization—markup insertion XSS. Patch: Latest xmldom https://www.tenable.com/cve/newest https://nvd.nist.gov/vuln/detail/CVE-2026-34601 https://github.com/jindw/xmldom/security/advisories/GHSA-...

    Post summary

    The tweet announces a high severity XML injection vulnerability in xmldom (CVE-2026-34601) and notes that the latest xmldom contains a patch.

    100007
    492 followersView on X
  • IntegSec@integ_sec
    Disclosure

    CVE-2026-34601: @xmldom/xmldom XML Injection - What It Means for Your Business and How to Respond https://hubs.li/Q04bdHcw0

    Post summary

    The text announces CVE-2026-34601, an XML‑injection flaw in the @xmldom/xmldom package, but offers no proof‑of‑concept, exploit code, or patch details.

    0000028
    28 followersView on X

Explore more