This advisory has been withdrawn because the maintainers of @xmldom/xmldom and multiple third parties disputed the validity of the issue. Attempts to create or replicate a proof of concept have been unsuccessful.
A prototype pollution vulnerability exists in the function copy in dom.js in the xmldom (published as @xmldom/xmldom) package.
Update to @xmldom/xmldom@~0.7.6, @xmldom/xmldom@~0.8.3 (dist-tag latest) or @xmldom/xmldom@>=0.9.0-beta.2 (dist-tag next).
None
https://github.com/xmldom/xmldom/pull/437
If you have any questions or comments about this advisory: * Email us at security@xmldom.org * Add information to https://github.com/xmldom/xmldom/issues/436
{
"github_reviewed": true,
"nvd_published_at": "2022-10-11T05:15:00Z",
"severity": "CRITICAL",
"github_reviewed_at": "2022-10-11T20:42:57Z",
"cwe_ids": [
"CWE-1321"
]
}