{"id":"CVE-2026-76572","summary":"pkp pkp-lib XSLTransformer.php _transformPHP xml external entity reference","details":"A vulnerability was detected in pkp pkp-lib up to 3.3.0-22/3.4.0-10/3.5.0-4. The affected element is the function _transformPHP of the file classes/xslt/XSLTransformer.php. The manipulation results in xml external entity reference. The attack can be executed remotely. Upgrading to version 3.3.0-23, 3.4.0-11 and 3.5.0-5 is sufficient to fix this issue. The patch is identified as 78c699370ea43ae2784e1c4ace7c947d207f2b47. Upgrading the affected component is advised.","modified":"2026-08-22T03:31:18.308561040Z","published":"2026-08-19T19:30:10.341Z","database_specific":{"cna_assigner":"VulDB","cwe_ids":["CWE-610","CWE-611"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/76xxx/CVE-2026-76572.json"},"references":[{"type":"WEB","url":"https://github.com/pkp/pkp-lib/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/76xxx/CVE-2026-76572.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-76572"},{"type":"ADVISORY","url":"https://vuldb.com/cve/CVE-2026-76572"},{"type":"ADVISORY","url":"https://vuldb.com/submit/878359"},{"type":"ADVISORY","url":"https://vuldb.com/vuln/393037"},{"type":"REPORT","url":"https://github.com/pkp/pkp-lib/issues/12977"},{"type":"REPORT","url":"https://vuldb.com/vuln/393037/cti"},{"type":"FIX","url":"https://github.com/pkp/pkp-lib/commit/78c699370ea43ae2784e1c4ace7c947d207f2b47"},{"type":"FIX","url":"https://github.com/pkp/pkp-lib/releases/tag/3_5_0-5"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/pkp/pkp-lib","events":[{"introduced":"fda81987b3f3ba6cf72097023246bf6a93ddebdc"},{"fixed":"78c699370ea43ae2784e1c4ace7c947d207f2b47"},{"fixed":"8b5f0fdc8d5664000b8652002781a14bd406bf21"}],"database_specific":{"extracted_events":[{"introduced":"3.3.0-22"},{"last_affected":"3.3.0-22"},{"introduced":"3.4.0-10"},{"last_affected":"3.4.0-10"},{"introduced":"3.5.0-4"},{"last_affected":"3.5.0-4"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["3.3.0-22","3.4.0-10","3.5.0-4"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-76572.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X"}]}