CVE-2026-41674 | xmldom prior 0.8.13/0.9.10 internalSubset/publicId/systemId xml injection (GHSA-f6ww-3ggp-fr8h / Nessus ID 313072)
A vulnerability, which was classified as critical, was found in xmldom. This affects an unknown function. The manipulation of the argument internalSubset/publicId/systemId results in xml injection.
This vulnerability is identified as CVE-2026-41674. The attack can be executed remotely. There is not any exploit available.
You should upgrade the affected component.