XML External Entity Vulnerability in W3CSS Validator by Google
CVE-2025-1781

8.4HIGH

Key Information:

Vendor

W3c

Vendor
CVE Published:
28 March 2025

What is CVE-2025-1781?

The W3CSS Validator prior to cssval-20250226 is susceptible to an XML External Entity (XXE) vulnerability. This flaw allows attackers to send specially-crafted XML objects that can lead to server-side request forgery (SSRF). If successful, an attacker could exploit this vulnerability to access sensitive local files on the server, particularly if they can manage to trigger exception messages. Organizations using this validator must update to the latest version to mitigate potential security risks associated with this vulnerability.

Affected Version(s)

CSS Validator < cssval-20250226

References

CVSS V4

Score:
8.4
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.