THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-27p8-2357-5qqv (high) — xmldom: DocType `name` Injection Bypasses requireWellFormed

[GHSA] GHSA-27p8-2357-5qqv (high) — xmldom: DocType `name` Injection Bypasses requireWellFormed

highgithub_advisoriesPublished 2026-09-08

GHSA-27p8-2357-5qqv Severity: high CVE: CVE-2026-83608

xmldom: DocType `name` Injection Bypasses requireWellFormed

## Summary

The `@xmldom/xmldom` serializer emits `DocumentType.name` verbatim into the `<!DOCTYPE …>` declaration with no well-formedness guard. GHSA-f6ww-3ggp-fr8h (CVE-2026-41674) hardened the serializer's `requireWellFormed` path for a DocumentType's sibling fields — `publicId`,

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-27p8-2357-5qqv