A pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module.
92%
Total Score
100
100
82
100
0
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-370943 @xmldom/xmldom is vulnerable to Regular Expression Denial of Service (ReDoS) in versions 0.9.0 - 0.9.10. | 0.9.0 - 0.9.10 | High |
AIKIDO-2026-814651 @xmldom/xmldom is vulnerable to XML Injection in versions 0.9.0 - 0.9.10 and 0.7.0 - 0.8.13. | 0.7.0 - 0.8.130.9.0 - 0.9.10 | High |
AIKIDO-2026-784472 @xmldom/xmldom is vulnerable to XML Injection in versions 0.9.0 - 0.9.10 and 0.7.0 - 0.8.13. | 0.7.0 - 0.8.130.9.0 - 0.9.10 | High |
CVE-2026-41673 @xmldom/xmldom is vulnerable to Uncontrolled Recursion in versions 0.0.0 - 0.8.13 and 0.9.0 - 0.9.10. | 0.0.0 - 0.8.130.9.0 - 0.9.10 | High |
CVE-2026-41674 @xmldom/xmldom is vulnerable to XML Injection (aka Blind XPath Injection) in versions 0.0.0 - 0.8.13 and 0.9.0 - 0.9.10. | 0.0.0 - 0.8.130.9.0 - 0.9.10 | High |
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant