Junglewise Threat Intelligence

CVE-2025-66371: PYSEC-2026-1765 - Peppol-py is vulnerable to XXE attacks due to Saxon configuration

CVE-2025-66371 · Severity: low · CVSS 3.1 · Published 2026-07-07

Vendors: PyPI.

Executive brief

peppol-py is a Python library for validating XML-based business invoices using the Peppol e-invoice standard. Due to insecure Saxon XML parser configuration, an authenticated attacker can exploit XXE (XML External Entity) attacks to read arbitrary files from the server's filesystem and exfiltrate their contents, potentially exposing sensitive configuration files or credentials.

Technical details

The vulnerability is an XML External Entity (XXE) injection (CWE-611) caused by the Saxon XML processor being configured with default settings that permit resolution of external DTDs and file/HTTP URLs. During XML invoice validation, an attacker can craft a malicious XML payload containing external entity declarations that reference local files (e.g., /etc/passwd) or remote servers. The attack requires authentication/authorization to submit XML invoices for validation. An attacker can read arbitrary files from the server and optionally exfiltrate them to attacker-controlled hosts. The fix, available in version 1.1.1, explicitly disables external URL access in the Saxon processor configuration.

Affected products

  • iterasdev peppol-py before 1.1.1

Timeline

  • 2025-11-28: disclosed: GHSA-24hm-wm2h-h8w7 published
  • 2025-11-13: patched: Fix merged in PR #16
  • 2025-12-01: other: GitHub security advisory reviewed

References