basicsecurity.net
Proof, not just disclosure.
Threats / Xerox FreeFlow Core / CVE-2025-8355
CVE-2025-8355 · EUVD no mirror located7 · GCVE no mirror located8 Verified 2026-08-11

Xerox FreeFlow Core XXE to server-side request forgery

Xerox FreeFlow Core parses attacker-supplied XML without disabling external entities, letting an unauthenticated attacker inject external entity references and coerce the server into making requests to internal resources (SSRF). Horizon3 discovered it alongside the companion RCE flaw, and it is not yet on the CISA KEV catalog.

Verdict

Lab-proven exploitable, ahead of the catalog.

Horizon3 discovered this XML external entity flaw in FreeFlow Core and reported it to Xerox, which fixes it in 8.0.5. Exploited, it yields server-side request forgery — reaching internal resources — and pairs with the companion path-traversal RCE (CVE-2025-8356) found in the same research. It is not on the CISA KEV catalog as of 2026-08-11 and no in-the-wild actor is attributed, so we track it as a lab-proof coverage lead surfaced early, not a known-exploited today-item. Patch to 8.0.5 and take FreeFlow Core off the public internet.

CISA KEV No · not listed as of 2026-08-113Horizon3 proven Yes · NodeZero-attributed weakness4EPSS ~0.07 · 93rd percentile (verify live)6Exploit Public PoC4CVSS 7.5 High1
01

Is it exploitable?

— the evidence, ranked above the score
Proven exploitable (Horizon3)
Horizon3.ai researcher Jimi Sebree discovered the XML external entity flaw in FreeFlow Core alongside the companion path-traversal RCE and detailed the XXE-to-SSRF chain in the attack-research write-up. Horizon3 reports proven weaknesses, not theoretical scanner findings.We cite the existence of Horizon3's proof and public analysis; we do not host or redistribute payloads.
Horizon3 ↗Confirmed
Not on CISA KEV (coverage lead)
As of 2026-08-11 this CVE — and every Xerox CVE — is absent from the CISA Known Exploited Vulnerabilities catalog. We surface it early on the strength of Horizon3's proof, ahead of the catalog, rather than waiting for KEV to catch up.This is a coverage lead, not a KEV removal. Re-check the KEV catalog at the cited source for the current listing.
CISA KEV ↗Confirmed
Exploit available
Public technical write-ups demonstrate crafting malicious XML with external entity references to force the server into server-side request forgery against internal URLs.
Horizon3 ↗Confirmed
Probability (EPSS)
EPSS around 0.07 with a ~93rd-percentile ranking as of the snapshot date.EPSS is a daily-changing model output — we cite the source rather than freeze a number. Open the source for today's value.
Affected / fixed
FreeFlow Core 8.0.4 is affected; Xerox fixes both CVE-2025-8355 and CVE-2025-8356 in FreeFlow Core 8.0.5 per Security Bulletin XRX25-013. NVD scores the base CVSS 7.5 (High). Exact affected build and remediation in the vendor bulletin and NVD.
02

Who’s exploiting it?

— attribution turns risk into urgency
Attribution not established

No confirmed (advisory-backed) threat-actor attribution is established for this record. Absence of a named actor is not absence of compromise — see Coverage & confidence.

03

Why it matters

— the attack path, told twice: adversary, then board
1

Front door — unauthenticated XML injection narrative 1

Attacker
No credentials. I submit XML the server will parse and embed an external entity reference pointing at an internal URL of my choosing.
Business
An attacker-supplied document is enough to make your print server start reaching into your network.
2

Pivot — server-side request forgery narrative 2

Attacker
The server dutifully fetches the internal resource I named, letting me probe and reach systems that are not exposed to the internet directly.
Business
Your internet-facing appliance becomes a relay into the internal network behind it — the kind of reach that chains into deeper compromise.
04

What to do

— defensible action
  • Patch to FreeFlow Core 8.0.5, which fixes both CVE-2025-8355 and CVE-2025-8356. Per Xerox Security Bulletin XRX25-013.5
  • Take FreeFlow Core off the public internet and restrict its outbound access, so an XXE-driven request cannot reach sensitive internal services. Treat instances exposed while unpatched as needing review.4
Say it to the boardHorizon3 found this flaw in the same research that produced a proven remote-code-execution bug in Xerox FreeFlow Core. On its own it lets an unauthenticated attacker turn your print server into a relay into the internal network, and it is not yet on the government's known-exploited list. Patch 8.0.5 and get it off the internet.
05

Coverage & confidence

— what we know, and what we don’t

Established (cited)

  • Mechanism, CVSS 7.5, CWE-611 (NVD, CVE.org)
  • Discovery attribution + proof (Horizon3)
  • Fixed build 8.0.5 (Xerox Bulletin XRX25-013)
  • EPSS ranking (FIRST)
  • Coverage gaps — stated, not hidden

  • Not on CISA KEV as of 2026-08-11 — no government known-exploited confirmation; tracked as a lab-proof lead.
  • No confirmed in-the-wild exploitation or named threat actor — absence of a headline actor is honest, not an omission.
  • NVD (7.5, integrity impact) and the Xerox CNA (7.5, confidentiality impact) differ on the CVSS vector — we cite both sources rather than assert one.
  • No EUVD / GCVE mirror located — single-authority dependency for the identifier.
  • EPSS is time-varying; we link the source rather than freeze a stale number.
  • Disclosure & credit2
    Catalogued by XeroxCNA
    Credited with finding itJimi Sebree (Horizon3.ai)finder
    Found an error? Propose a correction.

    A correction is a cited counter-claim — it must cite a source, gets reviewed by a second human, and is never auto-applied. See the correction convention and our identity npub1j7gt9ky7sfcrjn8jjee6693dkzvk4rahs0fk2suu7968dfns62zs3mqm3y.

    Corrections must cite a source.

    Paste into your Nostr client; it will sign with your key and publish.