THREAT OPS › Threat News › [GHSA] GHSA-27p8-2357-5qqv (high) — xmldom: DocType `name` Injection Bypasses requireWellFormed
[GHSA] GHSA-27p8-2357-5qqv (high) — xmldom: DocType `name` Injection Bypasses requireWellFormed
GHSA-27p8-2357-5qqv Severity: high CVE: CVE-2026-83608
xmldom: DocType `name` Injection Bypasses requireWellFormed
## Summary
The `@xmldom/xmldom` serializer emits `DocumentType.name` verbatim into the `<!DOCTYPE …>` declaration with no well-formedness guard. GHSA-f6ww-3ggp-fr8h (CVE-2026-41674) hardened the serializer's `requireWellFormed` path for a DocumentType's sibling fields — `publicId`,
MITRE ATT&CK techniques
- JavaScriptT1059.007
Indicators of compromise
- bb7a085dc5ba1eea3212388509b97bb4b4af32b9sha1
- e5c14802592685bb872c042c54c3f73758875c85sha1
- c80a161172cc4d8733583bf0cf59abfa589f6d9esha1
- CVE-2026-83608cve
- CVE-2026-41674cve
Original source: https://github.com/advisories/GHSA-27p8-2357-5qqv