{"id":"GHSA-f6rx-hf55-4255","summary":"Sulu vulnerable to XXE in SVG File upload Inspector","details":"### Impact\n\nA admin user can upload SVG which may load external data via XML DOM library, specially this can be used for eventually reference none secure XML External Entity References.\n\n### Patches\n\nThe problem has not been patched yet. Users should upgrade to patched versions once they become available. Currently affected versions are:\n\n - 2.6.9\n - 2.5.25\n - 3.0.0-alpha3\n\n### Workarounds\n\nPatch the effect file `src/Sulu/Bundle/MediaBundle/FileInspector/SvgFileInspector.php` in sulu with:\n\n```diff\n-$dom-\u003eloadXML($svg, \\LIBXML_NOENT | \\LIBXML_DTDLOAD);\n+$dom-\u003eloadXML($data, LIBXML_NONET);\n```\n\n### References\n\n - GitHub repository: https://github.com/sulu/sulu\n - Vulnerable code: https://github.com/sulu/sulu/blob/2.6/src/Sulu/Bundle/MediaBundle/FileInspector/SvgFileInspector.php","aliases":["CVE-2025-47778"],"modified":"2025-05-15T16:42:21.740609Z","published":"2025-05-15T16:08:02Z","database_specific":{"nvd_published_at":"2025-05-14T16:15:29Z","cwe_ids":["CWE-611"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2025-05-15T16:08:02Z"},"references":[{"type":"WEB","url":"https://github.com/sulu/sulu/security/advisories/GHSA-f6rx-hf55-4255"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-47778"},{"type":"WEB","url":"https://github.com/sulu/sulu/commit/02f52fca04eb9495b9b4a0c5cc64cf23bc27f544"},{"type":"PACKAGE","url":"https://github.com/sulu/sulu"},{"type":"WEB","url":"https://github.com/sulu/sulu/blob/2.6/src/Sulu/Bundle/MediaBundle/FileInspector/SvgFileInspector.php"}],"affected":[{"package":{"name":"sulu/sulu","ecosystem":"Packagist","purl":"pkg:composer/sulu/sulu"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.5.21"},{"fixed":"2.5.25"}]}],"versions":["2.5.21","2.5.22","2.5.23","2.5.24"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/05/GHSA-f6rx-hf55-4255/GHSA-f6rx-hf55-4255.json"}},{"package":{"name":"sulu/sulu","ecosystem":"Packagist","purl":"pkg:composer/sulu/sulu"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.6.5"},{"fixed":"2.6.9"}]}],"versions":["2.6.5","2.6.6","2.6.7","2.6.8"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/05/GHSA-f6rx-hf55-4255/GHSA-f6rx-hf55-4255.json"}},{"package":{"name":"sulu/sulu","ecosystem":"Packagist","purl":"pkg:composer/sulu/sulu"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"3.0.0-alpha1"},{"fixed":"3.0.0-alpha3"}]}],"versions":["3.0.0-alpha1","3.0.0-alpha2"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/05/GHSA-f6rx-hf55-4255/GHSA-f6rx-hf55-4255.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U"}]}