Lucee Server Remote Code Execution Vulnerability via XML External Entity Attack

Vulnerability

A remote code execution vulnerability has been identified in Lucee Server, all prior versions, through an XML external entity (XXE) attack on the Lucee REST endpoint. This issue arises from improper handling of XML data, allowing maliciously crafted XML to be processed in a way that executes arbitrary code on the server.

Impact

Exploitation of this vulnerability allows for remote code execution on the server where Lucee is running.

Remediation

Users should upgrade to Lucee versions 5.4.3.2, 5.3.12.1, 5.3.7.59, 5.3.8.236, or 5.3.9.173, all of which have been patched. Instructions for upgrading can be found in the Lucee GitHub repository.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
7.4
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.