HF RL Explorer

XML External Entity (XXE) Vulnerability Assessment

XML External Entity (XXE) Vulnerability Assessment: a task in openthoughts-tblite-dev-apptainer-v1: OpenThoughts-TBLite dev (offline Apptainer, v1) (Harbor dataset). A document processing service accepts XML input through multiple parser endpoints. Security auditors suspect one or more parsers may…

The task

A document processing service accepts XML input through multiple parser endpoints. Security auditors suspect one or more parsers may be vulnerable to XXE attacks. Your task is to identify vulnerable parsers, demonstrate exploitation, and implement secure alternatives.

Part of laion/openthoughts-tblite-dev-apptainer-v1.