CVE-2026-41672Disclosure

LOWCVSS 8.7 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) `DOMParser` and `XMLSerializer` module. In @xmldom/xmldom prior to versions 0.9.10 and 0.8.13 and xmldom version 0.6.0 and prior, the package allows attacker-controlled comment content to be serialized into XML without validating or neutralizing comment-breaking sequences. As a result, an attacker can terminate the comment early and inject arbitrary XML nodes into the serialized output. This issue has been patched in versions @xmldom/xmldom versions 0.9.10 and 0.8.13.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-91

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-05-07: 3Patch / Workaround · 2026-05-07: 1Technical Details · 2026-05-07: 105-07
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-41672 📊 Severity: 8.7 🚨 Risk Level: High 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-41672 #CVE-2026-41672 #CVE #High #CyberSecurity #InfoSec https://t.co/kb4jQjWOpf

    Post summary

    The tweet announces CVE-2026-41672 with a high severity rating but provides only minimal information, lacking technical details, PoC, exploit code, or patch guidance.

    0000059
    155 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-41672 xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) `DOMParser` and `XMLSerializer` module. In @xmldom/xmldom prior to versions 0.9.10 and 0.8.13 an… https://www.cve.org/CVERecord?id=CVE-2026-41672

    Post summary

    The post announces CVE-2026-41672 affecting the xmldom module before versions 0.9.10 and 0.8.13, indicating that these newer releases presumably patch the issue, without providing deeper technical details or exploit information.

    0000091
    57.4K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-41672 XML Injection via Unvalidated Comment Content in xmldom Prior to 0.9.10 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-41672

    Post summary

    The post discloses CVE-2026-41672, detailing an XML injection vulnerability in xmldom before version 0.9.10, but does not mention PoCs, exploit tools, active exploitation, or patches.

    0000035
    4.0K followersView on X

Explore more