It's possible to get access and read configuration files by using URLs such as http://localhost:8080/bin/ssx/Main/WebHome?resource=../../WEB-INF/xwiki.cfg&minify=false.
This can apparently be reproduced on Tomcat instances.
This has been patched in 17.4.0-rc-1, 16.10.7.
There is no known workaround, other than upgrading XWiki.
If you have any questions or comments about this advisory:
* Open an issue in Jira XWiki.org
* Email us at Security Mailing List
The vulnerability was reported by Gregor Neumann.
| Score | Percentile |
|---|---|
| 0.42% | 62.02% |
| Base score | Version | Severity | Vector |
|---|---|---|---|
| 9.3 | 4.0 | — |
|
| Type | Value |
|---|---|
| GHSA | GHSA-m63c-3rmg-r2cf ↗ |
| CVE | CVE-2025-55748 ↗ |
| CWE id | Name |
|---|---|
| CWE-23 | Relative Path Traversal |
Vulnerable version ranges and first patched releases as published by GitHub.
| Ecosystem | Package | Vulnerable range | First patched | Vulnerable functions |
|---|---|---|---|---|
| maven | org.xwiki.platform:xwiki-platform-skin-skinx | >= 4.2-milestone-2, < 16.10.7 | 16.10.7 | — |