VDB
Sign up
CRITICAL9.8

GHSA-crh6-fp67-6883

xmldom allows multiple root nodes in a DOM

Quick fix

GHSA-crh6-fp67-6883 — @xmldom/xmldom: upgrade to the fixed version with the command below.

npm install @xmldom/xmldom@0.7.7

Details

### Impact xmldom parses XML that is not well-formed because it contains multiple top level elements, and adds all root nodes to the `childNodes` collection of the `Document`, without reporting any error or throwing. This breaks the assumption that there is only a single root node in the tree, which led to https://nvd.nist.gov/vuln/detail/CVE-2022-39299 and is a potential issue for dependents.

### Patches Update to `@xmldom/xmldom@~0.7.7`, `@xmldom/xmldom@~0.8.4` (dist-tag `latest`) or `@xmldom/xmldom@>=0.9.0-beta.4` (dist-tag `next`).

### Workarounds One of the following approaches might help, depending on your use case: - Instead of searching for elements in the whole DOM, only search in the `documentElement`. - Reject a document with a document that has more then 1 `childNode`.

### References - https://nvd.nist.gov/vuln/detail/CVE-2022-39299 - https://github.com/jindw/xmldom/issues/150

### For more information If you have any questions or comments about this advisory: * Email us at security@xmldom.org

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/xmldom
Introduced in: 0

No fixed version published yet for xmldom (npm). Pin to a known-safe version or switch to an alternative.

npm/@xmldom/xmldom
Introduced in: 0Fixed in: 0.7.7
Fixnpm install @xmldom/xmldom@0.7.7
npm/@xmldom/xmldom
Introduced in: 0.8.0Fixed in: 0.8.4
Fixnpm install @xmldom/xmldom@0.8.4
npm/@xmldom/xmldom
Introduced in: 0.9.0-beta.1Fixed in: 0.9.0-beta.4
Fixnpm install @xmldom/xmldom@0.9.0-beta.4

References