CVE-2025-66372
Severity CVSS v4.0:
Pending analysis
Type:
CWE-611
Improper Restriction of XML External Entity Reference ('XXE')
Publication date:
28/11/2025
Last modified:
28/11/2025
Description
Mustang before 2.16.3 allows exfiltrating files via XXE attacks.
Impact
Base Score 3.x
2.80
Severity 3.x
LOW



