CVE-2026-76572: pkp pkp-lib XSLTransformer.php _transformPHP xml external entity reference
A vulnerability was detected in pkp pkp-lib up to 3.3.0-22/3.4.0-10/3.5.0-4. The affected element is the function transformPHP of the file classes/xslt/XSLTransformer.php. The manipulation results in xml external entity reference. The attack can be executed remotely. Upgrading to version 3.3.0-23, 3.4.0-11 and 3.5.0-5 is sufficient to fix this issue. The patch is identified as 78c699370ea43ae2784e1c4ace7c947d207f2b47. Upgrading the affected component is advised.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
pkp/pkp-libto a version that resolves this vulnerability.Fixed in 3.3.0-23Patch 78c699370ea43ae2784e1c4ace7c947d207f2b47 - Upgrade
Upgrade
pkp/pkp-libto a version that resolves this vulnerability.Fixed in 3.4.0-11Patch 78c699370ea43ae2784e1c4ace7c947d207f2b47 - Upgrade
Upgrade
pkp/pkp-libto a version that resolves this vulnerability.Fixed in 3.5.0-5Patch 78c699370ea43ae2784e1c4ace7c947d207f2b47
Event History
Frequently Asked Questions
Which installations need to be upgraded?
pkp-lib installations up to versions 3.3.0-22, 3.4.0-10, and 3.5.0-4 are affected. Upgrade to 3.3.0-23, 3.4.0-11, or 3.5.0-5, respectively.
Can this be exploited remotely?
Yes. The vulnerability is described as remotely executable and affects the _transformPHP function in classes/xslt/XSLTransformer.php.
Is an attacker required to have privileges?
The provided severity vector lists PR:H, indicating that high privileges are required. No user interaction is required according to the UI:N metric.
Is a patch identifier available for validating remediation?
Yes. The referenced patch identifier is 78c699370ea43ae2784e1c4ace7c947d207f2b47.