PT-2025-36708 · Pypi · Xml2Rfc
Published
2025-08-26
·
Updated
2025-08-26
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Impact
When generating PDF files, this vulnerability allows an attacker to read arbitrary files from the filesystem by injecting malicious link element into the XML.
Workarounds
Test untrusted input with
link elements with rel="attachment" before processing.Credits
This vulnerability was reported by Mohamed Ouad from Doyensec.
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Xml2Rfc