Home » Database

AVID-2026-R0881

Description

Improper Restriction of XML External Entity Reference in stanfordnlp/corenlp (CVE-2021-3869)

Details

corenlp is vulnerable to Improper Restriction of XML External Entity Reference

Reason for inclusion in AVID: CVE-2021-3869 affects stanfordnlp/corenlp, a library used in AI/NLP pipelines. It is a known security vulnerability (XML External Entity Reference) in a software component commonly used to build AI systems, representing a software supply chain concern. The report includes CVE details, affected artifact, and references, enabling curation.

References

Affected or Relevant Artifacts

  • Developer: stanfordnlp
  • Deployer: stanfordnlp
  • Artifact Details:
TypeName
Systemstanfordnlp/corenlp

Impact

AVID Taxonomy Categorization

  • Risk domains: Security
  • SEP subcategories: S0100: Software Vulnerability
  • Lifecycle stages: L06: Deployment

CVSS

Version3.0
Vector StringCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L
Base Score8.6
Base Severity🔴 High
Attack VectorNETWORK
Attack Complexity🟢 Low
Privileges RequiredNONE
User InteractionNONE
ScopeUNCHANGED
Confidentiality Impact🔴 High
Integrity Impact🟢 Low
Availability Impact🟢 Low

CWE

IDDescription
CWE-611CWE-611 Improper Restriction of XML External Entity Reference

Other information

  • Report Type: Advisory
  • Credits:
  • Date Reported: 2021-10-19
  • Version: 0.3.3
  • AVID Entry