CVE-2022-37616: Critical severity xmldom vulnerability

Published Oct 11, 2022
·
Updated

A prototype pollution vulnerability exists in the function copy in dom.js in the xmldom (published as @xmldom/xmldom) package before 0.8.3 for Node.js via the p variable. NOTE: the vendor states "we are in the process of marking this report as invalid"; however, some third parties takes the position that "A prototype injection/Prototype pollution is not just when global objects are polluted with recursive merge or deep cloning but also when a target object is polluted."

Affected Software

5 affected components
Xmldom Project Xmldom Node.js<=0.6.0
Xmldom Project Xmldom Node.js>=0.7.0<0.7.6
Xmldom Project Xmldom Node.js>=0.8.0<0.8.3
Xmldom Project Xmldom Node.js=0.9.0-beta1
Debian Debian Linux=10.0

Event History

Oct 11, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description

Frequently Asked Questions

1

What is the severity of CVE-2022-37616?

CVE-2022-37616 is classified as a prototype pollution vulnerability, which can have a moderate to high severity depending on the context of its exploitation.

2

How do I fix CVE-2022-37616?

To fix CVE-2022-37616, you should upgrade the xmldom package to version 0.8.3 or later.

3

What impact can CVE-2022-37616 have on my application?

CVE-2022-37616 can allow an attacker to manipulate object properties through prototype pollution, potentially leading to application instability or security bypasses.

4

Is CVE-2022-37616 present in all versions of xmldom?

No, CVE-2022-37616 affects versions of xmldom prior to 0.8.3.

5

Which platforms are affected by CVE-2022-37616?

CVE-2022-37616 affects Node.js applications that utilize the xmldom package.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203