xmldom npm Package Vulnerability: Early Warning
- Severity
- HIGH
- Affected component
- xmldom (npm)
- Affected versions
- >= 0.7.0, < 0.8.15 or >= 0.9.0, < 0.9.12 or <= 0.6.0 or < 0.8.13 or >= 0.9.0, < 0.9.10 or <= 0.6.0 or >= 0.9.0, < 0.9.11 or >= 0.7.0, < 0.8.14 or <= 0.6.0 or <= 0.6.0 or < 0.7.0 or >= 0.7.0, < 0.8.15 or >= 0.9.0, < 0.9.12 or <= 0.6.0 or >= 0.7.0, < 0.8.15 or >= 0.9.0, < 0.9.12 or <= 0.6.0 or >= 0.7.0, < 0.8.15 or >= 0.9.0, < 0.9.12 or <= 0.6.0 or >= 0.7.0, < 0.8.15 or >= 0.9.0, < 0.9.12 or >= 0.3.0, <= 0.6.0 or >= 0.7.0, < 0.8.15 or >= 0.9.0, < 0.9.12 or >= 0.1.5, <= 0.6.0 or >= 0.7.0, < 0.8.15 or >= 0.9.0, < 0.9.12 or <= 0.6.0 or <= 0.6.0 or < 0.7.7 or >= 0.8.0, < 0.8.4 or >= 0.9.0-beta.1, < 0.9.0-beta.4 or < 0.8.13 or >= 0.9.0, < 0.9.10 or <= 0.6.0 or < 0.5.0 or < 0.8.13 or >= 0.9.0, < 0.9.10 or <= 0.6.0 or >= 0.9.0, < 0.9.11 or >= 0.7.0, < 0.8.14 or <= 0.6.0 or <= 0.6.0 or < 0.8.12 or >= 0.9.0, < 0.9.9 or < 0.8.13 or >= 0.9.0, < 0.9.10 or <= 0.6.0
- Patched version
- Not yet available
An early warning has been issued for a vulnerability in the xmldom npm package. This vulnerability, which is under investigation, may affect various versions of the package.
What happened
The xmldom npm package reportedly has a vulnerability where creation-time XML Name/QName validation is bypassable via an embedded line terminator. This allows injection on the default serialization path. The vulnerability is tracked under GHSA-3PX3-54CX-RMW9 and was first flagged on 2026-09-08T21:02:33+00:00. It is not yet confirmed to be exploited in the wild.
To assess your exposure, review the affected components and version ranges provided. The vulnerability appears to affect multiple versions of the xmldom package, including but not limited to versions >= 0.7.0, < 0.8.15 or >= 0.9.0, < 0.9.12 or <= 0.6.0.
What to do about it
- Monitor the xmldom package for any patches or updates related to this vulnerability.
- Consider using alternative libraries until a fix is released for the xmldom package.
- Review your project dependencies to identify if you are using an affected version of the xmldom package.
- If you are using an affected version, plan to migrate to a non-vulnerable version as soon as a patch is available.
- No official fix has been published yet. Monitor the primary sources for updates.
How 0Day would have caught this
xmldom is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.
Frequently asked questions
Am I affected?
You may be affected if you are using the xmldom npm package in versions >= 0.7.0, < 0.8.15 or >= 0.9.0, < 0.9.12 or <= 0.6.0. Consult the primary sources for the complete list of affected versions.
What should I do right now?
Monitor for patches and consider using alternative libraries until a fix is released for the xmldom package.
Is there a patched version available?
No official fix has been published yet. Monitor the primary sources for updates.