org.xwiki.rendering:xwiki-rendering-xml has an Eval Injection issue
Summary
| CVE | CVE-2025-53837 |
|---|---|
| State | PUBLISHED |
| Assigner | GitHub_M |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-09-18 16:17:03 UTC |
| Updated | 2026-09-24 21:25:27 UTC |
| Description | XWiki Rendering is a generic rendering system that converts textual input in a given syntax (wiki syntax, HTML, etc) into another syntax (XHTML, etc). Prior to versions 14.10.2 and 15.0 RC1, any user who can edit their own user profile or any other document can execute arbitrary script macros including Groovy and Python macros that allow remote code execution including unrestricted read and write access to all wiki contents. The reason is that rendering output is included as content of HTML macros without further escaping and it is thus possible to close the HTML macro and inject script macros that are executed with programming rights. This has been patched in XWiki 14.10.2 and 15.0 RC1 by making sure that rendering output cannot close the surrounding HTML macro. A possible workaround is available. It is, in principle, possible to add escaping to all places where rendering output is used in wiki documents, but at the moment there is no list of them. |
Risk And Classification
Primary CVSS: v3.1 9.9 CRITICAL from [email protected]
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
EPSS: 0.006420000 probability, percentile 0.486020000 (date 2026-09-25)
Problem Types: CWE-95 | CWE-95 CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Secondary | 9.9 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
| 3.1 | CNA | DECLARED | 9.9 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
LowUser Interaction
NoneScope
ChangedConfidentiality
HighIntegrity
HighAvailability
HighCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Xwiki | Xwiki-rendering | affected < 14.10.2 | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| github.com/xwiki/xwiki-rendering/releases/tag/xwiki-rendering-15.0-rc-1 | [email protected] | github.com | |
| github.com/xwiki/xwiki-rendering/commit/92bc8095ed3acce15ab200c8525e1623... | [email protected] | github.com | |
| jira.xwiki.org/browse/XWIKI-20327 | [email protected] | jira.xwiki.org | |
| jira.xwiki.org/browse/XRENDERING-693 | [email protected] | jira.xwiki.org | |
| jira.xwiki.org/browse/XWIKI-20313 | [email protected] | jira.xwiki.org | |
| github.com/xwiki/xwiki-rendering/releases/tag/xwiki-rendering-14.10.2 | [email protected] | github.com | |
| github.com/xwiki/xwiki-rendering/security/advisories/GHSA-26vp-8gxg-v4pg | [email protected] | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.