Vulnerability record · CVE-2025-63917 · published 17 November 2025
CVE-2025-63917: Cnblogs pdfpatcher xml external entity (xxe) vulnerability
Cnblogs · Pdfpatcher
PDFPatcher thru 1.1.3.4663 executable's XML bookmark import functionality does not restrict XML external entity (XXE) references. The application uses .NET's XmlDocument class without disabling external entity resolution, enabling attackers to: Read arbitrary files from the victim's filesystem, exfiltrate sensitive data via out-of-band (OOB) HTTP requests, perform SSRF attacks against internal network resources, or cause a denial of service via entity expansion attacks.
Description
PDFPatcher thru 1.1.3.4663 executable's XML bookmark import functionality does not restrict XML external entity (XXE) references. The application uses .NET's XmlDocument class without disabling external entity resolution, enabling attackers to: Read arbitrary files from the victim's filesystem, exfiltrate sensitive data via out-of-band (OOB) HTTP requests, perform SSRF attacks against internal network resources, or cause a denial of service via entity expansion attacks.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:L
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/cydtseng/Vulnerability-Research/blob/main/pdfpatcher/XXE-Importers.md | ExploitThird Party Advisory |
| https://github.com/wmjordan/PDFPatcher | Product |
| https://www.cnblogs.com/pdfpatcher | Product |
Track CVE-2025-63917 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2025-63917), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.