CVE-2025-47293

LOW

Com.powsybl Powsybl-commons < 6.7.2 - SSRF

Title source: rule
STIX 2.1

Description

PowSyBl (Power System Blocks) is a framework to build power system oriented software. Prior to version 6.7.2, in certain places, powsybl-core XML parsing is vulnerable to an XML external entity (XXE) attack and to a server-side request forgery (SSRF) attack. This allows an attacker to elevate their privileges to read files that they do not have permissions to, including sensitive files on the system. The vulnerable class is com.powsybl.commons.xml.XmlReader which is considered to be untrusted in use cases where untrusted users can submit their XML to the vulnerable methods. This can be a multi-tenant application that hosts many different users perhaps with different privilege levels. This issue has been patched in com.powsybl:powsybl-commons: 6.7.2.

Scores

CVSS v4 2.7
EPSS 0.0030
EPSS Percentile 53.0%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-611 CWE-918
Status published
Products (2)
com.powsybl/powsybl-commons 0 - 6.7.2Maven
powsybl/powsybl-core < 6.7.2
Published Jun 19, 2025
Tracked Since Feb 18, 2026