{"id":"CVE-2025-52888","summary":"Allure 2's xunit-xml-plugin Vulnerable to Improper XXE Restriction","details":"Allure 2 is the version 2.x branch of Allure Report, a multi-language test reporting tool. A critical XML External Entity (XXE) vulnerability exists in the xunit-xml-plugin used by Allure 2 prior to version 2.34.1. The plugin fails to securely configure the XML parser (`DocumentBuilderFactory`) and allows external entity expansion when processing test result .xml files. This allows attackers to read arbitrary files from the file system and potentially trigger server-side request forgery (SSRF). Version 2.34.1 contains a patch for the issue.","aliases":["GHSA-h7qf-qmf3-85qg"],"modified":"2026-08-12T14:52:45.595976Z","published":"2025-06-24T19:45:22.854Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-611"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/52xxx/CVE-2025-52888.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/52xxx/CVE-2025-52888.json"},{"type":"ADVISORY","url":"https://github.com/allure-framework/allure2/security/advisories/GHSA-h7qf-qmf3-85qg"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-52888"},{"type":"FIX","url":"https://github.com/allure-framework/allure2/commit/cbcb33719851ff70adce85d38e15d20fc58d4eb7"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/allure-framework/allure2","events":[{"introduced":"0"},{"fixed":"cbcb33719851ff70adce85d38e15d20fc58d4eb7"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"2.34.1"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["2.34.0","2.33.0","2.32.2","2.32.1","2.32.0","2.31.0","2.30.0","2.29.0","2.28.0","2.27.0","2.26.0","2.25.0","2.24.1","2.24.0","2.23.1","2.23.0","2.22.4","2.22.3","2.22.2","2.22.1","2.22.0","2.21.0","2.20.1","2.20.0","2.19.0","2.18.1","2.18.0","2.17.3","2.17.2","2.17.1","2.17.0","2.16.1","2.16.0","2.15.0","2.14.0","2.13.10","2.13.9","2.13.8","2.13.7","2.13.6","2.13.5","2.13.4","2.13.3","2.13.2","2.13.1","2.13.0","2.12.1","2.12.0","2.11.0","2.10.0","2.9.0","2.8.1","2.8.0","2.7.0","2.6.0","2.5.0","2.4.1","2.4.0","2.3.5","2.3.4","2.3.3","2.3.2","2.3.1","2.3","2.2.1","2.2.0","2.1.1","2.1.0","2.0.1","2.0.0","2.0-BETA8","2.0-BETA7","2.0-BETA6","2.0-BETA5","2.0-BETA4","2.0-BETA3","2.0-BETA1","2.0-M1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-52888.json","vanir_signatures_modified":"2026-08-12T14:52:45Z","vanir_signatures":[{"target":{"function":"parseAssemblies","file":"plugins/xunit-xml-plugin/src/main/java/io/qameta/allure/xunitxml/XunitXmlPlugin.java"},"deprecated":false,"digest":{"function_hash":"306665084698275754271298403960736752","length":779},"id":"CVE-2025-52888-4f59ef9a","signature_type":"Function","signature_version":"v1","source":"https://github.com/allure-framework/allure2/commit/cbcb33719851ff70adce85d38e15d20fc58d4eb7"},{"id":"CVE-2025-52888-57a5f30a","signature_type":"Function","signature_version":"v1","source":"https://github.com/allure-framework/allure2/commit/cbcb33719851ff70adce85d38e15d20fc58d4eb7","target":{"file":"plugins/trx-plugin/src/main/java/io/qameta/allure/trx/TrxPlugin.java","function":"parseTestRun"},"deprecated":false,"digest":{"function_hash":"135178666668278725455898737782359572285","length":1094}},{"deprecated":false,"digest":{"function_hash":"288783633896869246628333597682259730367","length":906},"id":"CVE-2025-52888-58d24958","signature_type":"Function","signature_version":"v1","source":"https://github.com/allure-framework/allure2/commit/cbcb33719851ff70adce85d38e15d20fc58d4eb7","target":{"file":"plugins/junit-xml-plugin/src/main/java/io/qameta/allure/junitxml/JunitXmlPlugin.java","function":"parseRootElement"}},{"deprecated":false,"digest":{"line_hashes":["78953468569187824650508940978650176443","31893405341176612071604524046748295539","44233781341740472992052807052115089080","300819377773353154026585649336989760870","18247116733533141350465639812546595413","190961620966404338085813685207632523670","68595444524908570544823433301425457522"],"threshold":0.9},"id":"CVE-2025-52888-9b7ef658","signature_type":"Line","signature_version":"v1","source":"https://github.com/allure-framework/allure2/commit/cbcb33719851ff70adce85d38e15d20fc58d4eb7","target":{"file":"plugins/xunit-xml-plugin/src/test/java/io/qameta/allure/xunitxml/XunitXmlPluginTest.java"}},{"digest":{"line_hashes":["108548270329693738507732256510016910008","65342309348964602261025500003250676951","298269491609109213026457298833151070560","229186480762164346539889870814340914707","175298230739719670414493397583520056490","170491529493559550574124490243962131880","316830192656806682707914104474119297789","158453309515139208116228058083280631313","90495878586744633530429699212958041714"],"threshold":0.9},"id":"CVE-2025-52888-c0eb6d6d","signature_type":"Line","signature_version":"v1","source":"https://github.com/allure-framework/allure2/commit/cbcb33719851ff70adce85d38e15d20fc58d4eb7","target":{"file":"plugins/xunit-xml-plugin/src/main/java/io/qameta/allure/xunitxml/XunitXmlPlugin.java"},"deprecated":false},{"signature_type":"Line","signature_version":"v1","source":"https://github.com/allure-framework/allure2/commit/cbcb33719851ff70adce85d38e15d20fc58d4eb7","target":{"file":"plugins/trx-plugin/src/test/java/io/qameta/allure/trx/TrxPluginTest.java"},"deprecated":false,"digest":{"line_hashes":["152369890500082540271692024414509930270","31893405341176612071604524046748295539","44233781341740472992052807052115089080","95048189597402216665807296915347204124","200589084144950886636121518545136936118","190961620966404338085813685207632523670","68595444524908570544823433301425457522"],"threshold":0.9},"id":"CVE-2025-52888-c10f60e8"},{"source":"https://github.com/allure-framework/allure2/commit/cbcb33719851ff70adce85d38e15d20fc58d4eb7","target":{"file":"plugins/trx-plugin/src/main/java/io/qameta/allure/trx/TrxPlugin.java"},"deprecated":false,"digest":{"line_hashes":["60883449274262812147819999078535316930","259517375042708458694274973390558176743","298269491609109213026457298833151070560","229186480762164346539889870814340914707","287904999812038710971384073217418328935","170491529493559550574124490243962131880","316830192656806682707914104474119297789","114140111651525463483440149537352012727","69190866908452466256138112409673798410"],"threshold":0.9},"id":"CVE-2025-52888-c776111a","signature_type":"Line","signature_version":"v1"},{"signature_version":"v1","source":"https://github.com/allure-framework/allure2/commit/cbcb33719851ff70adce85d38e15d20fc58d4eb7","target":{"file":"plugins/junit-xml-plugin/src/test/java/io/qameta/allure/junitxml/JunitXmlPluginTest.java"},"deprecated":false,"digest":{"threshold":0.9,"line_hashes":["152369890500082540271692024414509930270","31893405341176612071604524046748295539","44233781341740472992052807052115089080","194620141687167632251569088773621266696","236696450177024117549480664242775649340","190961620966404338085813685207632523670","68595444524908570544823433301425457522"]},"id":"CVE-2025-52888-ea5698a5","signature_type":"Line"},{"signature_version":"v1","source":"https://github.com/allure-framework/allure2/commit/cbcb33719851ff70adce85d38e15d20fc58d4eb7","target":{"file":"plugins/junit-xml-plugin/src/main/java/io/qameta/allure/junitxml/JunitXmlPlugin.java"},"deprecated":false,"digest":{"line_hashes":["60883449274262812147819999078535316930","259517375042708458694274973390558176743","298269491609109213026457298833151070560","229186480762164346539889870814340914707","118017098188901950235985325840704764400","170491529493559550574124490243962131880","234464912410947369507731668025848806556","39582423950373182321421072811866270905","214245995026705387851702924208301195536"],"threshold":0.9},"id":"CVE-2025-52888-f727fa2a","signature_type":"Line"}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}