CVE-2025-9375

XML Injection vulnerability in xmltodict allows Input Data Manipulation. This issue affects xmltodict: from 0.14.2 before 0.15.1.
CVSS

No CVSS.

Configurations

No configuration.

History

08 Sep 2025, 21:15

Type Values Removed Values Added
References
  • () https://github.com/martinblech/xmltodict/blob/v0.15.1/CHANGELOG.md -
  • () https://github.com/martinblech/xmltodict/commit/f98c90f071228ed73df997807298e1df4f790c33 -
Summary (en) XML Injection vulnerability in xmltodict allows Input Data Manipulation.This issue affects xmltodict: 0.14.2. (en) XML Injection vulnerability in xmltodict allows Input Data Manipulation. This issue affects xmltodict: from 0.14.2 before 0.15.1.

05 Sep 2025, 02:15

Type Values Removed Values Added
References
  • () https://docs.python.org/3/library/xml.sax.utils.html#xml.sax.saxutils.XMLGenerator -
  • () https://docs.python.org/3/library/xml.sax.utils.html#xml.sax.saxutils.escape -
  • () https://github.com/martinblech/xmltodict/issues/377#issuecomment-3255691923 -

01 Sep 2025, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-09-01 17:15

Updated : 2025-09-08 21:15


NVD link : CVE-2025-9375

Mitre link : CVE-2025-9375

CVE.ORG link : CVE-2025-9375


JSON object : View

Products Affected

No product.

CWE
CWE-91

XML Injection (aka Blind XPath Injection)