CVE-2025-35112: Atlassian Agiloft

Medium severity, CVSS 4.9. EPSS: 0.3% chance of exploitation in the next 30 days.

Agiloft Release 28 contains an XML External Entities vulnerability in any table that allows 'import/export', allowing an authenticated attacker to import the template file and perform path traversal on the local system files. Users should upgrade to Agiloft Release 31.

Affected products

  • Atlassian Agiloft: from 19, before 31 (fixed in 31)

Published 2025-08-26. Last modified 2026-06-17.