Critical severity9.8NVD Advisory· Published Feb 24, 2018· Updated Jun 17, 2026
CVE-2017-18197
CVE-2017-18197
Description
In mxGraphViewImageReader.java in mxGraph before 3.7.6, the SAXParserFactory instance in convert() is missing flags to prevent XML External Entity (XXE) attacks, as demonstrated by /ServerView.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
mxgraphnpm | < 3.7.6 | 3.7.6 |
Affected products
3- ghsa-coords2 versions
< 3.7.6+ 1 more
- (no CPE)range: < 3.7.6
- (no CPE)range: < 3.9.2-1.9
Patches
Vulnerability mechanics
References
5- github.com/jgraph/mxgraph/issues/124nvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-wvpv-8524-wg6xghsaADVISORY
- lists.debian.org/debian-lts-announce/2018/03/msg00002.htmlnvdThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2017-18197ghsaADVISORY
- github.com/jgraph/mxgraph/commit/97b3718db64a6ca9afb3382de2926eb8da660052ghsaWEB
News mentions
0No linked articles in our index yet.