PT-2026-39200 · Unknown · Solidcam-Gppl-Ide

Anzory

·

Published

2026-05-08

·

Updated

2026-05-09

·

CVE-2026-42212

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions SolidCAM-GPPL-IDE versions 1.0.0 through 1.0.1
Description Opening a .gpp file causes the language server to parse a companion .vmid file from the same directory. The VMID parser uses XDocument.Load(path) without XmlReaderSettings, which in .NET 8 allows Document Type Definition (DTD) processing. This enables XML External Entity (XXE) injection—a technique where an application processes external entities within an XML document—allowing a malicious .vmid file to disclose local files via external entity references, exhaust memory through recursive entity expansion, or cause a denial of service via oversized or deeply nested XML.
Recommendations Update to version 1.0.2.

Exploit

Fix

Resource Exhaustion

XML Entity Expansion

XXE

Weakness Enumeration

Related Identifiers

CVE-2026-42212

Affected Products

Solidcam-Gppl-Ide