Improper Removal of Sensitive Information Before Storage or Transfer in XWiki platform - CVE-2025-58049
Published: May 5, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper removal of sensitive information before storage or transfer in the PDF export job status serialization when processing a PDF export request in a background job. A remote privileged user can trigger a PDF export to disclose sensitive information.
The stored job status can include user cookies, including encrypted credentials, and the encryption key is stored in the same data directory by default.