CVE-2025-65482

CRITICAL

opensagres XDocReport 0.9.2-2.0.3 - XML External Entity Injection via Crafted .docx File

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2025-65482. PoCs published by AT190510-Cuong.

AI-analyzed exploit summary This repository provides a detailed technical analysis of CVE-2025-65482, an XXE vulnerability in XDocReport (versions <= 2.0.3). It includes root cause analysis, steps to reproduce, and mitigation strategies, but does not contain functional exploit code.

Description

An XML External Entity (XXE) vulnerability in opensagres XDocReport v0.9.2 to v2.0.3 allows attackers to execute arbitrary code via uploading a crafted .docx file.

Exploits (1)

nomisec WRITEUP 1 stars
by AT190510-Cuong · poc
https://github.com/AT190510-Cuong/CVE-2025-65482-XXE-

This repository provides a detailed technical analysis of CVE-2025-65482, an XXE vulnerability in XDocReport (versions <= 2.0.3). It includes root cause analysis, steps to reproduce, and mitigation strategies, but does not contain functional exploit code.

Classification
Writeup 95%
Attack Type
Info Leak
Complexity
Moderate
Reliability
Reliable
Target: XDocReport (fr.opensagres.xdocreport.document.docx) <= 2.0.3
No auth needed
Prerequisites: Ability to upload a crafted .docx file to a vulnerable application
devstral-2 · analyzed May 05, 2026 Full analysis →

Scores

CVSS v3 9.8
EPSS 0.0049
EPSS Percentile 38.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-611
Status published
Products (2)
fr.opensagres.xdocreport/fr.opensagres.xdocreport.document 0.9.2 - 2.0.4Maven
opensagres/xdocreport 0.9.2 - 2.0.3
Published Jan 20, 2026
Tracked Since Feb 18, 2026