[security][CVE-2026-83615] @xmldom/xmldom in desktop packaging #178
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Newly reported active High CVE from the 2026-09-16 scan. New means not previously reported by this automation; some disclosures predate this run. Correction: earlier scans incorrectly dropped Trivy status
fixed, which means a patch is available, not installed.CVE: CVE-2026-83615
Severity: High. CVSS: redhat: 7.5
Affected versions
Project impact
apps/desktop -> Electron Forge -> @electron/packager@18.4.4 -> plist@3.1.1 -> @xmldom/xmldom@0.9.10. packager dist/mac.js loadPlist reads and parses plist files; plist lib/parse.js calls DOMParser.parseFromString(xml, "text/xml") before validating the root element. A malicious or compromised plist can stall or exhaust the desktop packaging process. Trusted inputs reduce exposure; no web/API XML endpoint was found.
Advisory description
xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. Prior to @xmldom/xmldom versions 0.8.15 and 0.9.12, and in xmldom versions 0.1.5 through 0.6.0, appendElement in lib/sax.js uses _copy to clone the complete currentNSMap for each nested element that declares a new namespace prefix. Keeping every ancestor map live on the parse stack creates quadratic peak namespace-map storage, so a small highly compressible XML document can exhaust the process heap before application validation. This issue is fixed in @xmldom/xmldom versions 0.8.15 and 0.9.12; no fixed version is available for xmldom.
Remediation
Resolve @xmldom/xmldom to 0.9.12 or later, which fixes this group of parser flaws. Update both Bun lockfiles through the existing workspace workflow and validate desktop packaging. Until patched, accept only trusted plist inputs and apply build time/memory limits.
Run counters, globally deduplicated by CVE ID
unaddressed critical CVEs: 6
unaddressed medium/low CVEs: 184
unaddressed total CVEs: 271
These are unresolved installed-version matches after explicit exclusions, not a claim that every inherited component is remotely exploitable. One UNKNOWN-severity record is retained separately and excluded from the requested severity total. Python requirements and apt-installed Python packages are unpinned, so their deployed versions cannot be established from this repository.
Resolution checks
Paginated all 171 Forgejo issue records and 101 PRs; checked local all-ref history. No matching CVE report or clear fixing change was found for this CVE. Its CVE registry state is PUBLISHED without a disputed tag. Existing reports for other flaws in the same component do not establish a fix for this one.
Sources