PT-2025-39843 · Xml2Rfc · Xml2Rfc

CVE-2025-11059

·

Published

2025-09-10

·

Updated

2026-07-07

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions xml2rfc (affected versions not specified)
Description An issue occurs during the generation of PDF files where an attacker can read arbitrary files from the filesystem. This is achieved by injecting a malicious link element into the prepped RFCXML.
Recommendations Test untrusted input containing link elements with the rel="attachment" attribute before processing.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-11059
GHSA-9MV7-3C64-MMQW
PYSEC-2026-2057

Affected Products

Xml2Rfc