CVE-2025-52888 Information
Description
Allure 2 is the version 2.x branch of Allure Report a multi-language test reporting tool. A critical XML External Entity (XXE) vulnerability exists in the xunit-xml-plugin used by Allure 2 prior to version 2.34.1. The plugin fails to securely configure the XML parser (DocumentBuilderFactory) and allows external entity expansion when processing test result .xml files. This allows attackers to read arbitrary files from the file system and potentially trigger server-side request forgery (SSRF). Version 2.34.1 contains a patch for the issue.
Reference
https://github.com/allure-framework/allure2/commit/cbcb33719851ff70adce85d38e15d20fc58d4eb7 https://github.com/allure-framework/allure2/security/advisories/GHSA-h7qf-qmf3-85qg
Related CNNVD
CNNVD-202506-3122 (Published: 2025-06-24)
Share on: