EIP-2026-119674

PRE-CVE

ExpertGPS 6.38 - XML External Entity Injection

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-119674. PoCs published by Trent Gordon.

AI-analyzed exploit summary This exploit demonstrates an XXE (XML External Entity) injection vulnerability in ExpertGPS 6.38, allowing an attacker to exfiltrate local files by crafting a malicious .gpx file. The PoC includes a DTD file and a malicious XML payload that, when imported, sends the contents of a local file to an attacker-controlled server.

Description

ExpertGPS 6.38 - XML External Entity Injection

Exploits (1)

exploitdb WORKING POC
by Trent Gordon · textwebappsxml
https://www.exploit-db.com/exploits/48026

This exploit demonstrates an XXE (XML External Entity) injection vulnerability in ExpertGPS 6.38, allowing an attacker to exfiltrate local files by crafting a malicious .gpx file. The PoC includes a DTD file and a malicious XML payload that, when imported, sends the contents of a local file to an attacker-controlled server.

Classification
Working Poc 100%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: ExpertGPS 6.38
No auth needed
Prerequisites: Attacker-controlled server to host payload.dtd and receive exfiltrated data · Victim must import the crafted .gpx file
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026