Hugging Face Smolagents version 1.20.0 contains an XPath injection vulnerability in the search_item_ctrl_f function located in src/smolagents/vision_web_browser.py. The function constructs an XPath query by directly concatenating user-supplied input into the XPath expression without proper sanitization or escaping. This allows an attacker to inject malicious XPath syntax that can alter the intended query logic. The vulnerability enables attackers to bypass search filters, access unintended DOM elements, and disrupt web automation workflows. This can lead to information disclosure, manipulation of AI agent interactions, and compromise the reliability of automated web tasks. The issue is fixed in version 1.22.0.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small educational proof-of-concept for XPath injection, framed around CVE-2025-11844 in Hugging Face smolagents. It is not a full exploit framework; the main logic is in poc_exploit.py. The script accepts a local HTML file path and an optional keyword, launches headless Chrome through Selenium, opens the file via a file:// URL, and executes a malicious XPath expression built from unsanitized input. The injected payload closes the original string context and appends an additional contains(text(), ...) clause, demonstrating how attacker-controlled input can alter XPath semantics and enumerate unintended DOM nodes. Repository structure: README.md describes the claimed vulnerability, affected component (search_item_ctrl_f in vision_web_browser.py), and the insecure XPath pattern. poc_exploit.py is the executable PoC. mock_page.html is a minimal demo target containing a hidden secret value (SECRET_API_KEY_2026_XYZ) to show information disclosure. Monoalphabetic Cipher.html is a larger standalone HTML page that appears unrelated to the vulnerability itself but can serve as another local DOM target for testing XPath matching behavior. Main exploit capability: local browser-based DOM extraction through XPath injection. The PoC does not deliver code execution, persistence, or a shell; it demonstrates information disclosure by retrieving text content from matched elements and printing tag, id, and extracted text to the terminal. It filters out large container tags to keep output readable. Because it operates on local HTML files with Selenium, the practical attack vector here is local/file/browser simulation rather than direct remote exploitation. Overall, this is a valid PoC exploit demonstrating XPath injection impact, primarily unauthorized DOM traversal and data extraction.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
1 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.