PT-2025-26776 · Allure 2+1 · Allure 2+1

Derekhaber

·

Published

2025-06-24

·

Updated

2025-06-25

·

CVE-2025-52888

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Allure 2 versions prior to 2.34.1
Description: A critical XML External Entity (XXE) vulnerability exists in the xunit-xml-plugin used by Allure 2. The plugin fails to securely configure the XML parser (DocumentBuilderFactory) and allows external entity expansion when processing test result .xml files. This allows attackers to read arbitrary files from the file system and potentially trigger server-side request forgery (SSRF).
Recommendations: For versions prior to 2.34.1, update to version 2.34.1 to resolve the issue. As a temporary workaround, consider restricting access to the xunit-xml-plugin to minimize the risk of exploitation. Avoid using the DocumentBuilderFactory with default settings in the affected plugin until the issue is resolved.

Exploit

Fix

XXE

Weakness Enumeration

Related Identifiers

CVE-2025-52888
GHSA-H7QF-QMF3-85QG

Affected Products

Allure 2
Xunit-Xml-Plugin