Home » Database

AVID-2026-R0932

Description

Improper Restriction of XML External Entity Reference in stanfordnlp/corenlp (CVE-2022-0198)

Details

corenlp is vulnerable to Improper Restriction of XML External Entity Reference

Reason for inclusion in AVID: CVE-2022-0198 affects stanfordnlp/corenlp, a library used in NLP/AI pipelines. This is a software vulnerability in a dependency that can impact AI systems built, trained, or deployed with such tooling, fulfilling the software supply chain relevance for GP AI stacks. The CVE description, CWE-611, and references (NVD entry, commit) provide clear vulnerability and evidence.

References

Affected or Relevant Artifacts

  • Developer: stanfordnlp
  • Deployer: stanfordnlp
  • Artifact Details:
TypeName
Systemstanfordnlp/corenlp

Impact

AVID Taxonomy Categorization

  • Risk domains: Security
  • SEP subcategories: S0100: Software Vulnerability
  • Lifecycle stages: L06: Deployment

CVSS

Version3.0
Vector StringCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N
Base Score6.1
Base Severity🟠 Medium
Attack VectorLOCAL
Attack Complexity🟢 Low
Privileges RequiredNONE
User InteractionREQUIRED
ScopeUNCHANGED
Confidentiality Impact🔴 High
Integrity Impact🟢 Low
Availability ImpactNONE

CWE

IDDescription
CWE-611CWE-611 Improper Restriction of XML External Entity Reference

Other information

  • Report Type: Advisory
  • Credits:
  • Date Reported: 2022-01-13
  • Version: 0.3.3
  • AVID Entry