CVE 9.3 CRITICAL

Pachno 1.0.6 Wiki TextParser XML External Entity Injection_CVE-2026-40042

9.3 / 10
CRITICAL
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Description

Pachno 1.0.6 contains an XML external entity injection vulnerability that allows unauthenticated attackers to read arbitrary files by exploiting unsafe XML parsing in the TextParser helper. Attackers can inject malicious XML entities through wiki table syntax and inline tags in issue descriptions, comments, and wiki articles to trigger entity resolution via simplexml_load_string() without LIBXML_NONET restrictions.

AI Analysis

XML external entity injection vulnerability in Pachno 1.0.6 allows unauthenticated attackers to read arbitrary files

Basic Information

ID CVE-2026-40042
Source VulnCheck
Published Apr 13, 2026 at 18:10

Affected Product

Vendor pancho
Product Pachno
Version 1.0.6
Affected Versions pancho Pachno 1.0.6

CWE Classification

AI Assessment

AI Score 9.3 / 10
AI Severity Critical
Vendor pancho
Product Pachno
Version 1.0.6

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.