It's possible to get access and read configuration files by using URLs such as http://localhost:8080/bin/ssx/Main/WebHome?resource=../../WEB-INF/xwiki.cfg&minify=false.
This can apparently be reproduced on Tomcat instances.
This has been patched in 17.4.0-rc-1, 16.10.7.
There is no known workaround, other than upgrading XWiki.
If you have any questions or comments about this advisory:
The vulnerability was reported by Gregor Neumann.
{
"cwe_ids": [
"CWE-23"
],
"github_reviewed": true,
"github_reviewed_at": "2025-09-03T17:45:11Z",
"nvd_published_at": "2025-09-03T21:15:32Z",
"severity": "CRITICAL"
}