{"id":"CVE-2025-11059","aliases":["PYSEC-2026-2057"],"url":"https://o3.security/vulnerability/CVE-2025-11059","summary":"xml2rfc is vulnerable to arbitrary file reads through prepped files","details":"### Impact\n\nWhen generating PDF files, this vulnerability allows an attacker to read arbitrary files from the filesystem by injecting malicious link element into the prepped RFCXML.\n\n### Workarounds\n\nTest untrusted input with `link` elements with `rel=\"attachment\"` before processing.\n\n### References\nThis is related to [GHSA-cfmv-h8fx-85m7](https://github.com/ietf-tools/xml2rfc/security/advisories/GHSA-cfmv-h8fx-85m7).","published":"2025-09-10T20:44:58Z","modified":"2026-07-07T17:56:15.443208682Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"PyPI","name":"xml2rfc","fixedVersion":"3.30.2"}],"fix":{"url":"https://github.com/ietf-tools/xml2rfc/commit/73fb1c91fc62ac540bb6bd24f982f2becf84c1b0","label":"ietf-tools/xml2rfc@73fb1c9"},"references":[{"type":"WEB","url":"https://github.com/ietf-tools/xml2rfc/security/advisories/GHSA-9mv7-3c64-mmqw"},{"type":"WEB","url":"https://github.com/ietf-tools/xml2rfc/commit/73fb1c91fc62ac540bb6bd24f982f2becf84c1b0"},{"type":"PACKAGE","url":"https://github.com/ietf-tools/xml2rfc"},{"type":"WEB","url":"https://github.com/ietf-tools/xml2rfc/releases/tag/v3.30.2"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-07T17:56:15.443208682Z"}}