Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cfmv-h8fx-85m7

Опубликовано: 26 авг. 2025
Источник: github
Github: Прошло ревью
CVSS4: 8.7

Описание

xml2rfc has an arbitrary file read vulnerability

Impact

When generating PDF files, this vulnerability allows an attacker to read arbitrary files from the filesystem by injecting malicious link element into the XML.

Workarounds

Test untrusted input with link elements with rel="attachment" before processing.

Credits

This vulnerability was reported by Mohamed Ouad from Doyensec.

Пакеты

Наименование

xml2rfc

pip
Затронутые версииВерсия исправления

<= 3.30.0

3.30.1

8.7 High

CVSS4

Дефекты

CWE-22

8.7 High

CVSS4

Дефекты

CWE-22