MEDIUM5.0
PYSEC-2026-1765
Peppol-py is vulnerable to XXE attacks due to Saxon configuration
Quick fix
PYSEC-2026-1765 — peppol-py: upgrade to the fixed version with the command below.
pip install --upgrade 'peppol-py>=1.1.1'Details
Peppol-py before 1.1.1 allows XXE attacks because of the Saxon configuration. When validating XML-based invoices, the XML parser could read files from the filesystem and expose their content to a remote host.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2025-66371[ADVISORY]
- https://github.com/iterasdev/peppol-py/pull/16[WEB]
- https://github.com/iterasdev/peppol-py/commit/349a4bff8adb6205ea411bac8d7a06da0477abd7[WEB]
- https://github.com/iterasdev/peppol-py[PACKAGE]
- https://github.com/iterasdev/peppol-py/releases/tag/1.1.1[WEB]
- https://invoice.secvuln.info[WEB]
- https://pypi.org/project/peppol-py[PACKAGE]
- https://github.com/advisories/GHSA-24hm-wm2h-h8w7[ADVISORY]