CVE 4.4 MEDIUM

Server-Side Request Forgery (SSRF) in PlantUML Macro via ‘server’ parameter_CVE-2026-42140

4.4 / 10
MEDIUM
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:N

Description

PlantUML Macro is a macro for rendering UML diagrams from simple textual schemes. Prior to version 2.4.1, the PlantUML Macro is vulnerable to Server-Side Request Forgery (SSRF). The macro allows users to specify an alternative PlantUML server via the server parameter. However, the application does not validate the supplied URL. An attacker can supply an internal IP address or a malicious external URL. The XWiki server will attempt to connect to this URL to "render" the diagram. This issue has been patched in version 2.4.1.

Basic Information

ID CVE-2026-42140
Source GitHub_M
Published May 4, 2026 at 17:37

Affected Product

Vendor xwiki-contrib
Product macro-plantuml
Version < 2.4.1
Affected Versions xwiki-contrib macro-plantuml < 2.4.1

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.