PT-2026-25060 · Tolgee+1 · Tolgee+1

Simonkoeck

·

Published

2026-03-12

·

Updated

2026-04-08

·

CVE-2026-32251

CVSS v4.0

9.3

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:N
Name of the Vulnerable Software and Affected Versions Tolgee versions prior to 3.166.3
Description Tolgee is an open-source localization platform. Prior to version 3.166.3, the XML parsers used for importing Android XML resources (.xml) and .resx files do not disable external entity processing. An authenticated user with the ability to import translation files into a project can exploit this to read arbitrary files from the server and make server-side requests to internal services. Exploitation can involve reading files such as /etc/passwd and accessing environment secrets or cloud metadata credentials. This impacts multi-tenant deployments.
Recommendations Update to version 3.166.3 or later.

Exploit

Fix

RCE

XXE

Weakness Enumeration

Related Identifiers

CVE-2026-32251
GHSA-RCVV-64PQ-VXFX

Affected Products

Tolgee
Tolgee-Platform