id: PYSEC-2026-3391 published: "2026-07-09T16:49:44.956239Z" modified: "2026-07-13T16:07:21.318545Z" aliases: - CVE-2022-26661 - GHSA-cj78-rgw3-4h5p summary: Improper Restriction of XML External Entity Reference in trytond and proteus details: An XXE issue was discovered in Tryton Application Platform (Server) 5.x through 5.0.45, 6.x through 6.0.15, and 6.1.x and 6.2.x through 6.2.5, and Tryton Application Platform (Command Line Client (proteus)) 5.x through 5.0.11, 6.x through 6.0.4, and 6.1.x and 6.2.x through 6.2.1. An authenticated user can make the server parse a crafted XML SEPA file to access arbitrary files on the system. affected: - package: name: trytond ecosystem: PyPI purl: pkg:pypi/trytond ranges: - type: ECOSYSTEM events: - introduced: 5.0.0 - fixed: 5.0.46 - introduced: 6.0.0 - fixed: 6.0.16 - introduced: 6.1.0 - fixed: 6.2.6 versions: - 5.0.0 - 5.0.1 - 5.0.10 - 5.0.11 - 5.0.12 - 5.0.13 - 5.0.14 - 5.0.15 - 5.0.16 - 5.0.17 - 5.0.18 - 5.0.19 - 5.0.2 - 5.0.20 - 5.0.21 - 5.0.22 - 5.0.23 - 5.0.24 - 5.0.25 - 5.0.26 - 5.0.27 - 5.0.28 - 5.0.29 - 5.0.3 - 5.0.30 - 5.0.31 - 5.0.32 - 5.0.33 - 5.0.34 - 5.0.35 - 5.0.36 - 5.0.37 - 5.0.38 - 5.0.39 - 5.0.4 - 5.0.40 - 5.0.41 - 5.0.42 - 5.0.43 - 5.0.44 - 5.0.45 - 5.0.5 - 5.0.6 - 5.0.7 - 5.0.8 - 5.0.9 - 6.0.0 - 6.0.1 - 6.0.10 - 6.0.11 - 6.0.12 - 6.0.13 - 6.0.14 - 6.0.15 - 6.0.2 - 6.0.3 - 6.0.4 - 6.0.5 - 6.0.6 - 6.0.7 - 6.0.8 - 6.0.9 - 6.2.0 - 6.2.1 - 6.2.2 - 6.2.3 - 6.2.4 - 6.2.5 references: - type: ADVISORY url: https://nvd.nist.gov/vuln/detail/CVE-2022-26661 - type: WEB url: https://discuss.tryton.org/t/security-release-for-issue11219-and-issue11244/5059 - type: WEB url: https://foss.heptapod.net/tryton/tryton/-/issues/11219 - type: PACKAGE url: https://hg.tryton.org/trytond - type: WEB url: https://lists.debian.org/debian-lts-announce/2022/03/msg00016.html - type: WEB url: https://lists.debian.org/debian-lts-announce/2022/03/msg00017.html - type: WEB url: https://www.debian.org/security/2022/dsa-5098 - type: WEB url: https://www.debian.org/security/2022/dsa-5099 - type: PACKAGE url: https://pypi.org/project/trytond - type: ADVISORY url: https://github.com/advisories/GHSA-cj78-rgw3-4h5p severity: - type: CVSS_V3 score: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N