Executive brief
peppol-py is a Python library for validating XML-based business invoices using the Peppol e-invoice standard. Due to insecure Saxon XML parser configuration, an authenticated attacker can exploit XXE (XML External Entity) attacks to read arbitrary files from the server's filesystem and exfiltrate their contents, potentially exposing sensitive configuration files or credentials.
Technical details
The vulnerability is an XML External Entity (XXE) injection (CWE-611) caused by the Saxon XML processor being configured with default settings that permit resolution of external DTDs and file/HTTP URLs. During XML invoice validation, an attacker can craft a malicious XML payload containing external entity declarations that reference local files (e.g., /etc/passwd) or remote servers. The attack requires authentication/authorization to submit XML invoices for validation. An attacker can read arbitrary files from the server and optionally exfiltrate them to attacker-controlled hosts. The fix, available in version 1.1.1, explicitly disables external URL access in the Saxon processor configuration.
Affected products
- iterasdev peppol-py before 1.1.1
Timeline
- 2025-11-28: disclosed: GHSA-24hm-wm2h-h8w7 published
- 2025-11-13: patched: Fix merged in PR #16
- 2025-12-01: other: GitHub security advisory reviewed