CVE-2025-68463: Biopython is vulnerable to doctype XML external entity (XXE) injection through Bio.Entrez
(updated )
Bio.Entrez in Biopython through 1.86 allows doctype XXE.
References
- github.com/advisories/GHSA-x3vf-39hj-gxr4
- github.com/biopython/biopython
- github.com/biopython/biopython/blob/master/NEWS.rst
- github.com/biopython/biopython/commit/736c96f37b190732ecca9da80ad0cb9d4967214d
- github.com/biopython/biopython/issues/5109
- nvd.nist.gov/vuln/detail/CVE-2025-68463
- pypi.org/project/biopython/1.87
Code Behaviors & Features
Detect and mitigate CVE-2025-68463 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →