Skip to main content
Vulnerability Database/CVE-2025-53837

CVE-2025-53837: XWiki Rendering RCE Vulnerability

CVE-2025-53837 is a remote code execution flaw in XWiki Rendering that allows authenticated users to execute arbitrary Groovy and Python macros through improper output escaping. This post explains its impact, affected versions, and mitigation steps.

Published:

CVE-2025-53837 Overview

CVE-2025-53837 is a code injection vulnerability [CWE-95] in XWiki Rendering, the subsystem that converts wiki syntax and HTML into rendered output. Any authenticated user who can edit their own profile or another document can execute arbitrary script macros, including Groovy and Python macros. Successful exploitation grants remote code execution with programming rights and unrestricted read and write access to all wiki content. The flaw exists in versions prior to 14.10.2 and 15.0 RC1.

Critical Impact

Low-privileged wiki users can achieve remote code execution and full read/write access to wiki data by injecting script macros through unescaped rendering output inside HTML macros.

Affected Products

  • XWiki Rendering versions prior to 14.10.2
  • XWiki Rendering versions prior to 15.0 RC1
  • XWiki platform deployments consuming the affected rendering component

Discovery Timeline

  • 2026-09-18 - CVE-2025-53837 published to NVD
  • 2026-09-24 - Last updated in NVD database

Technical Details for CVE-2025-53837

Vulnerability Analysis

The vulnerability resides in how XWiki Rendering emits content produced by nested rendering into HTML macro output. The XHTML printer does not escape the closing sequence of a surrounding HTML macro. An authenticated attacker with edit rights on any document, including their own user profile, can craft content that terminates the enclosing HTML macro and injects a new script macro. The injected macro executes with the programming rights of the containing document, which typically permits Groovy and Python execution. This effectively converts a content-editing primitive into arbitrary code execution on the wiki server.

Root Cause

The underlying defect is a missing output-escaping contract between the XHTML wiki printer and the HTML macro. Rendering output was embedded directly into HTML macro content without neutralizing sequences that could close the macro. Because macro boundaries in XWiki syntax are textual, an unescaped closing marker allows the parser to reinterpret subsequent text as new macros. The fix at commit 92bc8095ed3acce15ab200c8525e1623b4898be5 modifies XHTMLWikiPrinter in xwiki-rendering-xml to prevent rendering output from closing the surrounding HTML macro.

Attack Vector

Exploitation requires a network-reachable XWiki instance and a valid account with edit rights on at least one document. The attacker edits a document, injects payload text that closes the HTML macro, and appends a Groovy or Python script macro. When the document is rendered, the injected macro executes server-side with programming rights. No user interaction from an administrator is needed for execution beyond normal page rendering.

java
// Patch excerpt: xwiki-rendering-xml/src/main/java/org/xwiki/rendering/renderer/printer/XHTMLWikiPrinter.java
import java.util.Arrays;
import java.util.LinkedHashMap;
import java.util.List;
import java.util.Map;

import org.apache.commons.lang3.StringUtils;
// Source: https://github.com/xwiki/xwiki-rendering/commit/92bc8095ed3acce15ab200c8525e1623b4898be5

Detection Methods for CVE-2025-53837

Indicators of Compromise

  • Document revisions containing {{/html}} sequences followed by {{groovy}} or {{python}} script macro blocks in unexpected locations such as user profiles.
  • Unexpected Groovy or Python process activity spawned by the XWiki Java process.
  • New or modified wiki pages authored by low-privileged accounts that render server-side scripts.
  • Outbound network connections from the XWiki host to attacker-controlled infrastructure following document edits.

Detection Strategies

  • Audit document XAR exports and revision history for embedded {{groovy}}, {{python}}, or {{velocity}} macros authored by non-administrative users.
  • Monitor XWiki application logs for macro execution events tied to edits on user profile documents.
  • Correlate document save events with subsequent script macro invocations in the same rendering cycle.

Monitoring Recommendations

  • Enable verbose logging on the rendering pipeline and forward events to a centralized log platform for retention and search.
  • Alert on child processes of the XWiki JVM that execute shells, package managers, or network utilities.
  • Track programming rights usage and flag documents that gain script execution capabilities outside change-control windows.

How to Mitigate CVE-2025-53837

Immediate Actions Required

  • Upgrade XWiki Rendering to version 14.10.2 or 15.0 RC1 or later without delay.
  • Review recently edited documents, especially user profiles, for injected script macros and revert malicious revisions.
  • Rotate credentials and secrets accessible to the XWiki service account if exploitation is suspected.
  • Restrict edit rights to trusted users until the patch is deployed.

Patch Information

The fix ships in XWiki Rendering 14.10.2 and XWiki Rendering 15.0 RC1. The corrective change is documented in the GitHub commit and tracked in Jira issue XRENDERING-693. Additional context is available in the GitHub Security Advisory GHSA-26vp-8gxg-v4pg.

Workarounds

  • Apply manual escaping around all locations in wiki documents where rendering output is embedded inside HTML macros, noting that an exhaustive list of affected sites is not published.
  • Remove or restrict the HTML macro from user-editable documents where feasible.
  • Limit programming rights and script rights to a minimal set of administrator-owned documents.
bash
# Verify the installed XWiki Rendering version and upgrade
mvn dependency:tree | grep xwiki-rendering
# Upgrade to a fixed release: 14.10.2 or 15.0 RC1 or later

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.