SCA: security update for org.xwiki.rendering:xwiki-rendering-transformation-macro (GHSA-32mf-57h2-64x9)

high Tenable Self-Hosted Container Security Plugin ID 428377

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- XWiki Rendering is a generic rendering system that converts textual input in a given syntax (wiki syntax,
HTML, etc) into another syntax (XHTML, etc). Starting in version 4.2-milestone-1 and prior to versions
13.10.11, 14.4.7, and 14.10, the default macro content parser doesn't preserve the restricted attribute of
the transformation context when executing nested macros. This allows executing macros that are normally
forbidden in restricted mode, in particular script macros. The cache and chart macros that are bundled in
XWiki use the vulnerable feature. This has been patched in XWiki 13.10.11, 14.4.7 and 14.10. To avoid the
exploitation of this bug, comments can be disabled for untrusted users until an upgrade to a patched
version has been performed. Note that users with edit rights will still be able to add comments via the
object editor even if comments have been disabled. (CVE-2025-53836)

See Also

https://github.com/advisories/GHSA-32mf-57h2-64x9

Plugin Details

Severity: High

ID: 428377

Version: Revision 1.7

Type: Local

Family: SCA Checks

Published: 7/15/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 6.9

Percentile: 97.07

Vendor

Vendor Severity: Critical

CVSS v2

Risk Factor: High

Base Score: 9

Temporal Score: 7

Vector: CVSS2#AV:N/AC:L/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2025-53836

CVSS v3

Risk Factor: High

Base Score: 8.8

Temporal Score: 7.9

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 7/14/2025

Vulnerability Publication Date: 7/14/2025

Reference Information

CVE: CVE-2025-53836