CVE-2025-68463Medium· 4.9▾ SunlitBiopython is vulnerable to doctype XML external entity (XXE) injection through Bio.Entrez
▾ Sunlit zone — Low / medium · no exploitation signal
impact 27 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.3%
0.3% → 0.3%
Bio.Entrez in Biopython through 1.86 allows doctype XXE.
biopython <= 1.86Refer to the advisory for the patched release.