CVE-2026-34601 is a high-severity XML injection vulnerability affecting xmldom versions 0.6.0 and prior, and @xmldom/xmldom prior to versions 0.8.12 and 0.9.9. The flaw allows an attacker to insert the CDATA terminator "]]>" into a CDATASection node, which is then improperly serialized as active XML markup. This enables XML structure injection and potential downstream business-logic manipulation. With a CVSS score of 7.5 (High), this vulnerability can be exploited remotely without authentication or user interaction, primarily impacting data integrity. There is currently no evidence of active exploitation, no public exploit code available, and community discussion remains minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Xmldom | Xmldom | @xmldom/xmldom < 0.8.12, @xmldom/xmldom >= 0.9.0, < 0.9.9, xmldom <= 0.6.0CNA affected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.