PT-2026-36886 · Xwiki · Plantuml Macro
Lukasz-Rybak
·
Published
2026-05-04
·
Updated
2026-05-05
·
CVE-2026-42140
CVSS v3.1
4.4
Medium
| Vector | AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
PlantUML Macro versions prior to 2.4.1
Description
PlantUML Macro, used for rendering UML diagrams from textual schemes, contains a Server-Side Request Forgery (SSRF) flaw. The application fails to validate the URL provided through the
server parameter, allowing an attacker to specify an internal IP address or a malicious external URL. Consequently, the XWiki server attempts to connect to the supplied URL to render the diagram.Recommendations
Update to version 2.4.1.
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Plantuml Macro