CVE-2025-1781

Severity CVSS v4.0:
HIGH
Type:
CWE-611 Improper Restriction of XML External Entity Reference ('XXE')
Publication date:
28/03/2025
Last modified:
01/08/2025

Description

There is a XXE in W3CSS Validator versions before cssval-20250226 that allows an attacker to use specially-crafted XML objects to coerce server-side request forgery (SSRF).  This could be exploited to read arbitrary local files if an attacker has access to exception messages.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:w3:css_validator:*:*:*:*:*:*:*:* 20250226 (excluding)