{"id":"GHSA-x3vf-39hj-gxr4","summary":"Biopython is vulnerable to doctype XML external entity (XXE) injection through Bio.Entrez","details":"Bio.Entrez in Biopython through 1.86 allows doctype XXE.","aliases":["CVE-2025-68463","PYSEC-2026-1221"],"modified":"2026-07-07T17:56:50.047071590Z","published":"2025-12-18T06:30:13Z","database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2025-12-18T22:16:29Z","nvd_published_at":"2025-12-18T06:15:50Z","cwe_ids":["CWE-611"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-68463"},{"type":"WEB","url":"https://github.com/biopython/biopython/issues/5109"},{"type":"WEB","url":"https://github.com/biopython/biopython/commit/736c96f37b190732ecca9da80ad0cb9d4967214d"},{"type":"WEB","url":"https://github.com/biopython/biopython"},{"type":"WEB","url":"https://github.com/biopython/biopython/blob/master/NEWS.rst"},{"type":"WEB","url":"https://pypi.org/project/biopython/1.87"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2026/05/08/16"}],"affected":[{"package":{"name":"biopython","ecosystem":"PyPI","purl":"pkg:pypi/biopython"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"1.86"}]}],"versions":["1.00a3","1.00a4","1.10","1.20","1.21","1.22","1.23","1.24","1.30","1.40b","1.41","1.42","1.43","1.44","1.45","1.46","1.47","1.48","1.49","1.49b","1.50","1.50b","1.51","1.51b","1.52","1.53","1.54","1.54b","1.55","1.55b","1.56","1.57","1.58","1.59","1.60","1.61","1.62","1.62b","1.63","1.63b","1.64","1.65","1.66","1.67","1.68","1.69","1.70","1.71","1.72","1.73","1.74","1.75","1.76","1.77","1.78","1.79","1.80","1.81","1.82","1.83","1.84","1.85","1.86"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/12/GHSA-x3vf-39hj-gxr4/GHSA-x3vf-39hj-gxr4.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:N/A:L"}]}