PT-2025-36708 · Pypi · Xml2Rfc

Published

2025-08-26

·

Updated

2025-08-26

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

Impact

When generating PDF files, this vulnerability allows an attacker to read arbitrary files from the filesystem by injecting malicious link element into the XML.

Workarounds

Test untrusted input with link elements with rel="attachment" before processing.

Credits

This vulnerability was reported by Mohamed Ouad from Doyensec.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

GHSA-CFMV-H8FX-85M7

Affected Products

Xml2Rfc