CVE-2025-6984
Last modified
CVE-2025-6984 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. The langchain-ai/langchain project, specifically the EverNoteLoader component, is vulnerable to XML External Entity (XXE) attacks due to insecure XML parsing. The affected version is 0.3.63. EPSS estimates a 1.53% chance of exploitation in the next 30 days.
Description
The langchain-ai/langchain project, specifically the EverNoteLoader component, is vulnerable to XML External Entity (XXE) attacks due to insecure XML parsing. The affected version is 0.3.63. The vulnerability arises from the use of etree.iterparse() without disabling external entity references, which can lead to sensitive information disclosure. An attacker could exploit this by crafting a malicious XML payload that references local files, potentially exposing sensitive data such as /etc/passwd.
Metrics
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-6984?
How severe is CVE-2025-6984?
How do I fix CVE-2025-6984?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-6982Use of Hard-coded Credentials in TP-Link Archer C50 V3( <= …6.9
- CVE-2025-69820Directory Traversal vulnerability in Beam beta9 v.0.1.521 al…6
- CVE-2025-69821An issue in Beat XP VEGA Smartwatch (Firmware Version - RB30…7.4
- CVE-2025-69822An issue in Atomberg Atomberg Erica Smart Fan Firmware Versi…7.4
- CVE-2025-69828File Upload vulnerability in TMS Global Software TMS Managem…10
- CVE-2025-6983A Clickjacking vulnerability in TP-Link Archer C1200 web m…5.1
- CVE-2025-69848NetBox is an open-source infrastructure resource modeling an…5.4
- CVE-2025-6985The HTMLSectionSplitter class in langchain-text-splitters ve…7.5
- CVE-2025-6986The FileBird – WordPress Media Library Folders & File Manage…6.5
- CVE-2025-6987The Advanced iFrame plugin for WordPress is vulnerable to St…6.4
- CVE-2025-69871A race condition vulnerability exists in MedusaJS Medusa v2.…8.1
- CVE-2025-69872DiskCache (python-diskcache) through 5.6.3 uses Python pickl…9.8
Are you affected by CVE-2025-6984?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
