CVE-2025-4639

HIGH

Peergos <1.1.0 - XML External Entity Reference

Title source: llm
STIX 2.1

Description

CWE-611 Improper Restriction of XML External Entity Reference in the getDocumentBuilder() method of WebDav servlet in Peergos. This issue affects Peergos through version 1.1.0.

Scores

CVSS v4 8.8
EPSS 0.0022
EPSS Percentile 45.0%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:L/SC:L/SI:N/SA:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-611
Status published
Products (1)
Peergos/Peergos 1.1.0
Published May 14, 2025
Tracked Since Feb 18, 2026