CVE-2025-43708

VisiCut 2.1 allows stack consumption via an XML document with nested set elements, as demonstrated by a java.util.HashMap StackOverflowError when reference='../../../set/set[2]' is used, aka an "insecure deserialization" issue.
Configurations

Configuration 1 (hide)

cpe:2.3:a:visicut:visicut:2.1:*:*:*:*:*:*:*

History

24 Sep 2025, 00:51

Type Values Removed Values Added
Summary
  • (es) VisiCut 2.1 permite el consumo de pila a través de un documento XML con elementos de conjunto anidados, como lo demuestra un java.util.HashMap StackOverflowError cuando se utiliza reference='../../../set/set[2]', también conocido como un problema de "deserialización insegura".
CPE cpe:2.3:a:visicut:visicut:2.1:*:*:*:*:*:*:*
First Time Visicut visicut
Visicut
References () https://github.com/Gelcon/PoC-of-VisiCut2_1-Stack-Overflow-Vul - () https://github.com/Gelcon/PoC-of-VisiCut2_1-Stack-Overflow-Vul - Exploit, Third Party Advisory
References () https://github.com/t-oster/VisiCut - () https://github.com/t-oster/VisiCut - Product
References () https://visicut.org - () https://visicut.org - Product

17 Apr 2025, 01:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-17 01:15

Updated : 2025-09-24 00:51


NVD link : CVE-2025-43708

Mitre link : CVE-2025-43708

CVE.ORG link : CVE-2025-43708


JSON object : View

Products Affected

visicut

  • visicut
CWE
CWE-674

Uncontrolled Recursion