Executive brief
Oinone Pamirs, an AI-powered low-code development framework, contains a vulnerability in how it processes XML data. An attacker can send specially crafted XML files to the system to trick it into revealing sensitive local files or making unauthorized network requests to internal systems. This could lead to the exposure of confidential configuration data or provide a foothold for further attacks on the internal network.
Technical details
An XML External Entity (XXE) vulnerability exists in Oinone Pamirs 7.0.0 due to insecure XStream-based XML parsing configurations. The vulnerability is located in the PamirsXmlUtils.fromXML() and ViewXmlUtils.fromXML() methods within the pamirs-framework-orm-xml and pamirs-boot-ui components. A remote, unauthenticated attacker can exploit this by submitting malicious XML payloads to any application endpoint, template import, or workflow that utilizes these utility methods. Successful exploitation allows for the resolution of external entities, enabling local file disclosure (LFD) and server-side request forgery (SSRF).
Affected products
- Oinone Pamirs Framework (Oinone Pamirs) 7.0.0
Timeline
- 2026-05-15: disclosed: Vulnerability details published via GitHub Gist and NVD.
- 2026-05-15: advisory