CVE-2025-35112: Agiloft XML external entity local path traversal
Published Aug 26, 2025
·Updated
Agiloft Release 28 contains an XML External Entities vulnerability in any table that allows 'import/export', allowing an authenticated attacker to import the template file and perform path traversal on the local system files. Users should upgrade to Agiloft Release 31.
Affected Software
2 affected components
Agiloft Agiloft<31
Atlassian Agiloft>=19<31
Event History
Aug 26, 2025
CVE Published
via MITRE·10:19 PM
Data Sourced
via MITRE·10:19 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-35112?
CVE-2025-35112 is considered a high-severity vulnerability due to its potential for path traversal attacks.
2
How do I fix CVE-2025-35112?
To fix CVE-2025-35112, users should upgrade to Agiloft Release 31 or later.
3
What type of vulnerability is CVE-2025-35112?
CVE-2025-35112 is characterized as an XML External Entities (XXE) vulnerability.
4
Who is affected by CVE-2025-35112?
CVE-2025-35112 affects users of Agiloft versions prior to Release 31.
5
Can an unauthenticated user exploit CVE-2025-35112?
No, CVE-2025-35112 can only be exploited by authenticated users with access to the template import/export functionality.