PT-2026-36886 · Xwiki · Plantuml Macro

·

CVE-2026-42140

·

Published

2026-05-04

·

Updated

2026-05-05

CVSS v3.1

4.4

Medium

VectorAV:N/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions PlantUML Macro versions prior to 2.4.1
Description PlantUML Macro, used for rendering UML diagrams from textual schemes, contains a Server-Side Request Forgery (SSRF) flaw. The application fails to validate the URL provided through the server parameter, allowing an attacker to specify an internal IP address or a malicious external URL. Consequently, the XWiki server attempts to connect to the supplied URL to render the diagram.
Recommendations Update to version 2.4.1.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-42140
GHSA-42FC-7W97-8VRC

Affected Products

Plantuml Macro