CVE-2025-52888 Details
Description
Allure 2 is the version 2.x branch of Allure Report, a multi-language test reporting tool. A critical XML External Entity (XXE) vulnerability exists in the xunit-xml-plugin used by Allure 2 prior to version 2.34.1. The plugin fails to securely configure the XML parser (`DocumentBuilderFactory`) and allows external entity expansion when processing test result .xml files. This allows attackers to read arbitrary files from the file system and potentially trigger server-side request forgery (SSRF). Version 2.34.1 contains a patch for the issue.
A critical XML External Entity (XXE) vulnerability has been identified in Allure 2, specifically in the xunit-xml-plugin, trx-plugin, and junit-xml-plugin, all prior to version 2.34.1. The vulnerability arises because the plugins do not properly configure the XML parser, allowing external entity expansion when test result XML files are processed. This flaw enables attackers to read arbitrary files from the file system and potentially execute server-side request forgery (SSRF) attacks. The issue has been patched in Allure 2.34.1.
Users can update to Allure version 2.34.1 or later, where this vulnerability has been patched.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 24, 2025CISA-ADP
Assessed Jun 24, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/allure-framework/allure2/commit/cbcb33719851ff70adce85d38e15d20fc58d4eb7 | [email protected] | Source CodeVendor |
| https://github.com/allure-framework/allure2/security/advisories/GHSA-h7qf-qmf3-85qg | [email protected] | AdvisoryExploitRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-611 | Improper Restriction of XML External Entity Reference | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| io.qameta.allure | All versions |
CPE
Remediation
| |
| io.qameta.allure.plugins:junit-xml-plugin | All versions |
CPE
Remediation
| |
| io.qameta.allure.plugins:trx-plugin | All versions |
CPE
Remediation
| |
| io.qameta.allure.plugins:xunit-xml-plugin | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 24, 2025 | New CVE Received | [email protected] |
Volerion