CVE-2025-11844
Last modified
CVE-2025-11844 is a medium-severity vulnerability rated 5.4/10 on the CVSS scale. Hugging Face Smolagents version 1.20.0 contains an XPath injection vulnerability in the search_item_ctrl_f function located in src/smolagents/vision_web_browser.py. The function constructs an XPath query by directly concatenating user-supplied input into the XPath expression without proper sanitization or escaping. EPSS estimates a 0.25% chance of exploitation in the next 30 days.
Description
Hugging Face Smolagents version 1.20.0 contains an XPath injection vulnerability in the search_item_ctrl_f function located in src/smolagents/vision_web_browser.py. The function constructs an XPath query by directly concatenating user-supplied input into the XPath expression without proper sanitization or escaping. This allows an attacker to inject malicious XPath syntax that can alter the intended query logic. The vulnerability enables attackers to bypass search filters, access unintended DOM elements, and disrupt web automation workflows. This can lead to information disclosure, manipulation of AI agent interactions, and compromise the reliability of automated web tasks. The issue is fixed in version 1.22.0.
Metrics
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Huggingface | Smolagents | >= 1.20.0, < 1.22.0 |
References
- https://huntr.com/bounties/01ab4405-9bca-4b26-b7a3-5ca1863a69b4Exploit, Third Party Advisory
- https://huntr.com/bounties/01ab4405-9bca-4b26-b7a3-5ca1863a69b4Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-11844?
How severe is CVE-2025-11844?
How do I fix CVE-2025-11844?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-11839A security flaw has been discovered in GNU Binutils 2.45. Im…5.5
- CVE-2025-1184A vulnerability was found in pihome-shc PiHome 1.77 and clas…8.8
- CVE-2025-11840A weakness has been identified in GNU Binutils 2.45. The aff…5.5
- CVE-2025-11841The Greenshift – animation and page builder blocks plugin fo…6.4
- CVE-2025-11842A security vulnerability has been detected in Shazwazza Smid…6.3
- CVE-2025-11843Therefore Corporation GmbH has recently become aware that Th…8.8
- CVE-2025-11845A null pointer dereference vulnerability in the certificate …4.9
- CVE-2025-11846A null pointer dereference vulnerability in the account sett…4.9
- CVE-2025-11847A null pointer dereference vulnerability in the IP settings …4.9
- CVE-2025-11848A null pointer dereference vulnerability in the Wake-on-LAN …4.9
- CVE-2025-11849Versions of the package mammoth from 0.3.25 and before 1.11.…9.3
- CVE-2025-1185A vulnerability was found in pihome-shc PiHome 2.0. It has b…8.8
Are you affected by CVE-2025-11844?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
