PT-2026-39200 · Unknown · Solidcam-Gppl-Ide

·

CVE-2026-42212

·

Published

2026-05-08

·

Updated

2026-05-09

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions SolidCAM-GPPL-IDE versions 1.0.0 through 1.0.1
Description Opening a .gpp file causes the language server to parse a companion .vmid file from the same directory. The VMID parser uses XDocument.Load(path) without XmlReaderSettings, which in .NET 8 allows Document Type Definition (DTD) processing. This enables XML External Entity (XXE) injection—a technique where an application processes external entities within an XML document—allowing a malicious .vmid file to disclose local files via external entity references, exhaust memory through recursive entity expansion, or cause a denial of service via oversized or deeply nested XML.
Recommendations Update to version 1.0.2.

Exploit

Fix

Resource Exhaustion

XML Entity Expansion

XXE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-42212
GHSA-92VG-F4FQ-FXM9

Affected Products

Solidcam-Gppl-Ide