CVE-2024-52800

Potential XXE (XML External Entity Injection) vulnerability in veraPDF CLI

Description

veraPDF is an open source PDF/A validation library. Executing policy checks using custom schematron files via the CLI invokes an XSL transformation that may theoretically lead to a remote code execution (RCE) vulnerability. This doesn't affect the standard validation and policy checks functionality, veraPDF's common use cases. Most veraPDF users don't insert any custom XSLT code into policy profiles, which are based on Schematron syntax rather than direct XSL transforms. For users who do, only load custom policy files from sources you trust. This issue has not yet been patched. Users are advised to be cautious of XSLT code until a patch is available.

Category

2.3
CVSS
Severity: Low
CVSS 4.0 •
EPSS 3.88% Top 15%
Affected: veraPDF veraPDF-library
Published at:
Updated at:

References

Frequently Asked Questions

What is the severity of CVE-2024-52800?
CVE-2024-52800 has been scored as a low severity vulnerability.
How to fix CVE-2024-52800?
To fix CVE-2024-52800, make sure you are using an up-to-date version of the affected component(s) by checking the vendor release notes. As for now, there are no other specific guidelines available.
Is CVE-2024-52800 being actively exploited in the wild?
It is possible that CVE-2024-52800 is being exploited or will be exploited in a near future based on public information. According to its EPSS score, there is a ~4% probability that this vulnerability will be exploited by malicious actors in the next 30 days.
What software or system is affected by CVE-2024-52800?
CVE-2024-52800 affects veraPDF veraPDF-library.
This platform uses data from the NIST NVD, MITRE CVE, MITRE CWE, First.org and CISA KEV but is not endorsed or certified by these entities. CVE is a registred trademark of the MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. CWE is a registred trademark of the MITRE Corporation and the authoritative source of CWE content is MITRE's CWE web site.
© 2025 Under My Watch. All Rights Reserved.