CVE-2026-83609
Summary
An embedded line terminator bypasses xmldom's always-on, WHATWG-mandated creation-time name
validation. createElementNS, createAttributeNS, createDocumentType, and createAttribute should
reject a malformed qualified name with InvalidCharacterError, but a name whose first line is
well-formed slips through and enters the DOM. On serialization it is emitted verbatim, so the
characters after the line terminator inject markup into the output. The injection reaches the default
serialization path, and enabling requireWellFormed does not prevent it.
Details
createElementNS, createAttributeNS, and createDocumentType route through validateQualifiedName,
and createAttribute performs the analogous check; each validates the name with
g.QName_exact.test(name). QName_exact = reg('^', QName, '$') inherits the m flag from xmldom's
shared regexp builder, so the matcher accepts any name whose first line is a valid QName and leaves
the remaining lines unconstrained (see Root Cause).
Root Cause
1. A shared regexp builder compiles anchored productions with the m flag.
2. ^…$ under m are line anchors, not string anchors.
3. validateQualifiedName / createAttribute validate with .test() against such a production, so a
line terminator followed by breakout markup passes and the malformed name is stored.
The triggering line terminators are the ECMAScript LineTerminator set: U+000A, U+000D, U+2028, U+2029.
Proof of Concept
const { DOMImplementation, XMLSerializer } = require('@xmldom/xmldom');
const impl = new DOMImplementation();
const doc = impl.createDocument('urn:x', 'root', null);
const el = doc.createElementNS('urn:x', 'a\n><script>x</script'); // ACCEPTED (no throw)
doc.documentElement.appendChild(el);
// DEFAULT serialization — requireWellFormed NOT set:
console.log(new XMLSerializer().serializeToString(doc));
// Observed: <root xmlns="urn:x"><a
// ><script>x</script/></root> <-- injected element on the default path
// Control: createElementNS('urn:x', 'bad>name') thro
⚡ Watch CVE-2026-83609
Get an email if CVE-2026-83609 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.
Exploitation outlook
- Low exploitation risk0.33% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 25% of all EPSS-scored CVEs.
Advisory coverage (2)
External references
Embed the live status
— this badge updates automatically when the KEV or exploit status changes. How to embed it →
[](https://www.csirts.com/cve/CVE-2026-83609)