Medium severityNVD Advisory· Published May 19, 2026· Updated Jun 17, 2026
CVE-2026-46722
CVE-2026-46722
Description
The OOXML parsing of the file indexer does not disable external entity resolution. A crafted xlsx or pptx document placed in an indexed directory can cause local files to be read or outbound HTTP requests to be performed, with the retrieved content being written to the search index.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
tpwd/ke_searchPackagist | >= 7.0.0, < 7.0.1 | 7.0.1 |
tpwd/ke_searchPackagist | >= 6.0.0, < 6.6.1 | 6.6.1 |
tpwd/ke_searchPackagist | >= 5.0.0, < 5.6.2 | 5.6.2 |
tpwd/ke_searchPackagist | < 4.6.7 | 4.6.7 |
Affected products
1Patches
Vulnerability mechanics
References
4News mentions
0No linked articles in our index yet.