XXE injection in Process Eval
| Advisory ID | GVD-2026-002 |
|---|---|
| CVSSv 4.0 Vector | CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H |
| CVSSv 4.0 Base Score | 8.9 |
| Severity | High |
| CVE | Pending |
| Date Published | 2026-07-27 |
| Description | An authenticated attacker with search access can craft a malicious XML payload with external entity references to read arbitrary files on the server (e.g., /etc/passwd ) or perform Server-Side Request Forgery (SSRF) attacks against internal services. |
| Affected Product | Eval v5.3.0 and earlier. |
| Solution | Upgrade to Eval v5.4.0. |
Comments
Article is closed for comments.