PT-2025-10615 · Locals3 · Locals3

Xbow-Security

·

Published

2025-03-10

·

Updated

2025-07-24

·

CVE-2025-27136

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
Name of the Vulnerable Software and Affected Versions LocalS3 versions prior to 1.21
Description The issue concerns XML External Entity (XXE) injection in the bucket creation endpoint. When processing the CreateBucketConfiguration XML document, the service's XML parser resolves external entities without proper validation, allowing an attacker to declare an external entity that references an internal URL. This enables server-side request forgery (SSRF) attacks, making requests to internal services or resources that should not be accessible from external networks, and potentially leaking sensitive information.
Recommendations For versions prior to 1.21, update to version 1.21 or later to resolve the issue. As a temporary workaround, consider restricting access to the bucket creation endpoint to minimize the risk of exploitation. Avoid using the CreateBucketConfiguration XML document with external entities until the issue is resolved.

Exploit

Fix

XXE

Weakness Enumeration

Related Identifiers

CVE-2025-27136
GHSA-G6WM-2V64-WQ36

Affected Products

Locals3