PT-2026-36886 · Xwiki · Plantuml Macro

Lukasz-Rybak

·

Published

2026-05-04

·

Updated

2026-05-05

·

CVE-2026-42140

CVSS v3.1

4.4

Medium

VectorAV:N/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions PlantUML Macro versions prior to 2.4.1
Description PlantUML Macro, used for rendering UML diagrams from textual schemes, contains a Server-Side Request Forgery (SSRF) flaw. The application fails to validate the URL provided through the server parameter, allowing an attacker to specify an internal IP address or a malicious external URL. Consequently, the XWiki server attempts to connect to the supplied URL to render the diagram.
Recommendations Update to version 2.4.1.

Fix

SSRF

Weakness Enumeration

Related Identifiers

CVE-2026-42140
GHSA-42FC-7W97-8VRC

Affected Products

Plantuml Macro