CVE-2025-11059High▾ Twilightxml2rfc is vulnerable to arbitrary file reads through prepped files
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
When generating PDF files, this vulnerability allows an attacker to read arbitrary files from the filesystem by injecting malicious link element into the prepped RFCXML.
Test untrusted input with link elements with rel="attachment" before processing.
This is related to GHSA-cfmv-h8fx-85m7.
xml2rfc < 3.30.2Upgrade to a patched release:
xml2rfc 3.30.2Connected by shared product, vendor, weakness, or advisory.