CVE-2026-41675: high-severity vulnerability in xmldom
xmldom: XML node injection through unvalidated processing instruction serialization
Published · Updated
No sign of exploitation. No public exploitation artifact known so far.
The xmldom library fails to properly escape special characters in XML processing instructions, allowing attackers to break out of the instruction and inject malicious XML code into the output. This can lead to data corruption or unauthorized content injection.
The vulnerability exists in the XMLSerializer component where attacker-controlled processing instruction data is serialized without neutralizing the PI-closing sequence (?>). An attacker can inject the sequence to prematurely terminate the processing instruction and inject arbitrary XML nodes. The attack requires control over processing instruction content and affects serialization operations.
In the same product, most dangerous first.