Oinone Pamirs 7.0.0 contains an XML External Entity (XXE) issue in its XStream-based XML parsing logic. When attacker-controlled XML is passed to framework parsing entry points such as PamirsXmlUtils.fromXML(...) or ViewXmlUtils.fromXML(...), unsafe XML processing can lead to file disclosure or SSRF.
References
Configurations
No configuration.
History
15 May 2026, 21:16
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-611 | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.5 |
15 May 2026, 15:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-15 15:16
Updated : 2026-05-18 17:44
NVD link : CVE-2026-39053
Mitre link : CVE-2026-39053
CVE.ORG link : CVE-2026-39053
JSON object : View
Products Affected
No product.
CWE
CWE-611
Improper Restriction of XML External Entity Reference
