PT-2026-25060 · Tolgee+1 · Tolgee+1
Simonkoeck
·
Published
2026-03-12
·
Updated
2026-04-08
·
CVE-2026-32251
CVSS v4.0
9.3
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:N |
Name of the Vulnerable Software and Affected Versions
Tolgee versions prior to 3.166.3
Description
Tolgee is an open-source localization platform. Prior to version 3.166.3, the XML parsers used for importing Android XML resources (.xml) and .resx files do not disable external entity processing. An authenticated user with the ability to import translation files into a project can exploit this to read arbitrary files from the server and make server-side requests to internal services. Exploitation can involve reading files such as
/etc/passwd and accessing environment secrets or cloud metadata credentials. This impacts multi-tenant deployments.Recommendations
Update to version 3.166.3 or later.
Exploit
Fix
RCE
XXE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tolgee
Tolgee-Platform