CVE-2026-6807 is an XML parsing vulnerability affecting all versions of GRASSMARLIN, including v3.2.1 as referenced in the source content. The flaw stems from insufficient hardening of the application's XML parsing process when opening stored GrassMarlin session data. GrassMarlin stores session information in XML files bundled into ZIP-based .gm3 archives; these session files contain graph and metadata elements such as nodes, edges, positioning, colors, and session metadata. Available reporting and public proof-of-concept analysis indicate the vulnerable attack surface is the XML content ingested when a user opens a crafted GrassMarlin session file. The issue is consistent with XML External Entity processing and is categorized as CWE-611. Public reporting indicates that a malicious DTD/external entity reference can be used to induce out-of-band exfiltration of local file contents during XML parsing.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small, functional proof-of-concept exploit for CVE-2026-6807 targeting Grassmarlin session import/parsing via XML external entity processing. It contains two Python scripts and a README. gen_payload.py creates a malicious .gm3 archive (a ZIP-like Grassmarlin session package) with a crafted session.xml that references an attacker-controlled external DTD. The DTD URL includes a target file path in the t= query parameter. The script also estimates how many entity references are needed by reading the same target locally when possible, then writes a package containing manifest.xml, session.xml, and several stub XML files. listener_relay.py is the attacker-side HTTP relay. When the victim requests /evil.dtd?t=<path>, the server reads the specified file path, base64-encodes it, splits it into 150-character chunks, and returns a DTD defining entities c0..cN. Each entity points to a callback URL /c?i=<idx>&d=<chunk>. As the vulnerable XML parser resolves those entities, it makes outbound HTTP GET requests carrying the file data chunk-by-chunk. The relay collects all chunks, reassembles and decodes them, and writes the recovered content to exfil_output.txt. Overall capability: arbitrary file read and out-of-band exfiltration from a vulnerable Grassmarlin environment, not code execution. The exploit is operational rather than a mere detector because it includes both payload generation and a working exfiltration listener. Notable constraints from the README: exploitation reportedly depends on Grassmarlin using its bundled/older Java runtime, and some file contents may need base64 chunking to avoid parser errors.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An XML External Entity (XXE) information disclosure vulnerability in GrassMarlin caused by insufficient hardening of the XML parsing process when opening stored session files.
An information disclosure vulnerability in the NSA-developed GrassMarlin OT/ICS networking tool caused by insufficient hardening of XML parsing, enabling XXE-style exploitation and out-of-band exfiltration of arbitrary files via malicious session files.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.