CVE-2026-83616 | xmldom up to 0.6.0/0.8.14/0.9.11 Processing Instruction lib/dom.js Document.createProcessingInstruction Target injection

SecurityVulns

A vulnerability was found in xmldom up to 0.6.0/0.8.14/0.9.11 and classified as critical. This affects the function Document.createProcessingInstruction of the file lib/dom.js of the component Processing Instruction. Executing a manipulation of the argument Target can lead to injection.

This vulnerability is tracked as CVE-2026-83616. The attack can be launched remotely. No exploit exists.

It is suggested to upgrade the affected component.VulDB Recent EntriesRead More