CVE-2021-32796: medium-severity vulnerability in xmldom
Misinterpretation of malicious XML input in xmldom
Published · Updated
No sign of exploitation. No public exploitation artifact known so far.
The xmldom library fails to properly escape special characters when removing XML elements from their parent structure, which can cause malicious XML input to be misinterpreted and potentially alter how downstream applications process the data.
xmldom ≤0.6.0 improperly escapes special characters during serialization of detached XML nodes, allowing an attacker to craft malicious XML documents that undergo unexpected syntactic transformations when processed by dependent applications; exploitation requires the application to parse and serialize untrusted XML content.
In the same product, most dangerous first.