VYPR
Medium severity6.5NVD Advisory· Published Mar 28, 2025· Updated Jun 17, 2026

CVE-2025-1781

CVE-2025-1781

Description

There is a XXE in W3CSS Validator versions before cssval-20250226 that allows an attacker to use specially-crafted XML objects to coerce server-side request forgery (SSRF).  This could be exploited to read arbitrary local files if an attacker has access to exception messages.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • Range: <cssval-20250226
  • W3C/CSS Validatorv5
    Range: < cssval-20250226

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.