CRITICAL ALERT: Apache Struts2 XXE Exposed (CVE-2025–68493)
ZAST.AI discovered a high severity XXE vulnerability in XWork-Core allows threat actors steal files & trigger SSRF.
CRITICAL ALERT: Apache Struts2 XXE Exposed (CVE-2025–68493)


ZAST.AI discovered a high severity XXE vulnerability in XWork-Core allows threat actors steal files & trigger SSRF.
The flaw was hidden in DomHelper’s unconfigured SAX parser.
⚡ Discovered by ZAST.ai AI Agent — proving once again that AI-driven logic beats pattern matching.
Patch immediately (Struts2 <= 6.0.3)!
🔗 Vulnerability reports: https://cwiki.apache.org/confluence/display/WW/S2-069
메타데이터
- post_id
- aba57becc5e6
- slug
- critical-alert-apache-struts2-xxe-exposed-cve-2025-68493-aba57becc5e6
- url
- https://medium.com/@zastxai/critical-alert-apache-struts2-xxe-exposed-cve-2025-68493-aba57becc5e6
- canonical_url
- https://medium.com/@zastxai/critical-alert-apache-struts2-xxe-exposed-cve-2025-68493-aba57becc5e6
- author_url
- https://medium.com/@zastxai
- status
- ok
- fetched_at
- 2026-06-25 07:00:49