Executive brief
Lutece Core is an open-source platform used by local authorities to manage digital services. A critical vulnerability in its XSL export feature allows authenticated administrators to execute arbitrary code on the server by uploading malicious XSL transformation files. This could lead to complete system compromise and unauthorized access to sensitive government data.
Technical details
The vulnerability exists in Lutece Core's XSL export management module, which processes XML/XSLT without enabling secure processing mode (FEATURE_SECURE_PROCESSING). This allows Java extension functions to be executed from attacker-controlled XSL stylesheets. An authenticated administrator can upload a manipulated XSL transformation file and trigger its execution during user export operations, achieving remote code execution on the server. The vulnerability affects versions up to 7.1.7, and a patch has been released in version 7.1.9.
Affected products
- Lutece Lutece Core up to 7.1.7
Timeline
- 2026-09-01: disclosed
- 2026-09-01: patched: Patch released in version 7.1.9