PT-2026-8312 · Unknown · Opencc Jflow

Maoqiu

·

Published

2026-02-16

·

Updated

2026-02-16

·

CVE-2026-2536

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions opencc JFlow versions prior to 20260129
Description A flaw exists in opencc JFlow’s Workflow Engine component, specifically within the Imp Done function of the src/main/java/bp/wf/httphandler/WF Admin AttrFlow.java file. This issue stems from the manipulation of the File argument, leading to XML External Entity (XXE) reference. The attack can be initiated remotely. The details of this issue have been publicly disclosed, and the project has been notified but has not yet responded.
Recommendations Update opencc JFlow to a version later than 20260129. As a temporary workaround, restrict access to the WF Admin AttrFlow.java file. Avoid using the File argument in the Imp Done function until the issue is resolved.

Exploit

Fix

XXE

Weakness Enumeration

Related Identifiers

CVE-2026-2536

Affected Products

Opencc Jflow