CVE-2025-66372: Mustangproject Mustang

Low severity, CVSS 2.8. EPSS: 0.1% chance of exploitation in the next 30 days.

Mustang before 2.16.3 allows exfiltrating files via XXE attacks.

Affected products

Published 2025-11-28. Last modified 2026-10-08.