Medium severityNVD Advisory· Published Sep 1, 2025· Updated Apr 20, 2026
CVE-2025-9375
CVE-2025-9375
Description
XML Injection vulnerability in xmltodict allows Input Data Manipulation. This issue affects xmltodict: from 0.14.2 before 0.15.1.
NOTE: the scope of this CVE is disputed by the vendor on the grounds that xmltodict.unparse() delegates element-name handling to Python's xml.sax.saxutils.XMLGenerator, and that XMLGenerator should be the component performing validation.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6- docs.python.org/3/library/xml.sax.utils.htmlnvd
- docs.python.org/3/library/xml.sax.utils.htmlnvd
- fluidattacks.com/advisories/mononvd
- github.com/martinblech/xmltodict/blob/v0.15.1/CHANGELOG.mdnvd
- github.com/martinblech/xmltodict/commit/f98c90f071228ed73df997807298e1df4f790c33nvd
- github.com/martinblech/xmltodict/issues/377nvd
News mentions
0No linked articles in our index yet.