CVE-2025-66372: Mustangproject Mustang
Low severity, CVSS 2.8. EPSS: 0.1% chance of exploitation in the next 30 days.
Mustang before 2.16.3 allows exfiltrating files via XXE attacks.
Affected products
- Mustangproject Mustang: before 2.16.3 (fixed in 2.16.3)
Published 2025-11-28. Last modified 2026-10-08.