CVE-2025-31497
Last modified
CVE-2025-31497 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. TEIGarage is a webservice and RESTful service to transform, convert and validate various formats, focussing on the TEI format. The Document Conversion Service contains a critical XML External Entity (XXE) Injection vulnerability in its document conversion functionality. EPSS estimates a 0.34% chance of exploitation in the next 30 days.
Description
TEIGarage is a webservice and RESTful service to transform, convert and validate various formats, focussing on the TEI format. The Document Conversion Service contains a critical XML External Entity (XXE) Injection vulnerability in its document conversion functionality. The service processes XML files during the conversion process but fails to disable external entity processing, allowing an attacker to read arbitrary files from the server's filesystem. This vulnerability could allow attackers to read sensitive files from the server's filesystem, potentially exposing configuration files, credentials, or other confidential information. Additionally, depending on the server configuration, this could potentially be used to perform server-side request forgery (SSRF) attacks by making the server connect to internal services. This issue is patched in version 1.2.4. A workaround for this vulnerability includes disabling external entity processing in the XML parser by setting the appropriate security features (e.g., XMLConstants.FEATURE_SECURE_PROCESSING).
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-31497?
How severe is CVE-2025-31497?
How do I fix CVE-2025-31497?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-31490AutoGPT is a platform that allows users to create, deploy, a…7.5
- CVE-2025-31491AutoGPT is a platform that allows users to create, deploy, a…8.6
- CVE-2025-31492mod_auth_openidc is an OpenID Certified authentication and a…8.2
- CVE-2025-31493Kirby is an open-source content management system. A vulnera…9.1
- CVE-2025-31494AutoGPT is a platform that allows users to create, deploy, a…3.5
- CVE-2025-31496apollo-compiler is a query-based compiler for the GraphQL qu…7.5
- CVE-2025-31498c-ares is an asynchronous resolver library. From 1.32.3 thro…8.3
- CVE-2025-31499Jellyfin is an open source self hosted media server. Version…8.8
- CVE-2025-3150A vulnerability was found in itning Student Homework Managem…5.3
- CVE-2025-31500Best Practical RT (Request Tracker) 5.0 through 5.0.7 allows…6.1
- CVE-2025-31501Best Practical RT (Request Tracker) 5.0 through 5.0.7 allows…6.1
- CVE-2025-3151A vulnerability was found in SourceCodester Gym Management S…9.8
Are you affected by CVE-2025-31497?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
