Intel

AIKIDO-2026-801403

GNOME.libxslt is vulnerable to Type Confusion

Type ConfusionCVE-2025-7424 Published Yesterday

75

High Risk

This Affects:

C++GNOME.libxslt
0.0.1 - 1.1.43
Fixed in 1.1.44
Are you affected? Scan for Free

TL;DR

When document() loads the stylesheet that is already running, libxslt uses that stylesheet document as the source document. Stylesheet nodes and source nodes share the psvi field, so a stylesheet that calls document() on itself makes the transform read psvi as the wrong type and can corrupt memory or crash the process. The fix copies the stylesheet document and clears psvi on the copy before reuse.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you transform untrusted XSLT that calls document() on the stylesheet itself.

Background info

GNOME.libxslt is vulnerable to Type Confusion in versions 0.0.1 - 1.1.43.

How to fix this

Upgrade the GNOME.libxslt library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform