PT-2025-51994 · Pypi+1 · Biopython+1

Hartwork

+1

·

Published

2025-12-18

·

Updated

2026-05-11

·

CVE-2025-68463

CVSS v3.1

4.9

Medium

VectorAV:N/AC:H/PR:L/UI:N/S:C/C:L/I:N/A:L
Name of the Vulnerable Software and Affected Versions Biopython versions prior to 1.87
Description Bio.Entrez in Biopython allows doctype XML External Entity (XXE), which is a technique where an XML parser is tricked into processing external entities within a document type definition, potentially leading to unauthorized access to local files or server-side request forgery.
Recommendations Update to version 1.87.

Fix

XXE

Weakness Enumeration

Related Identifiers

CVE-2025-68463
GHSA-X3VF-39HJ-GXR4
OPENSUSE-SU-2026:10537-1

Affected Products

Biopython
Debian