CVE-2025-7425: exploitation status and patch state

CVE-2025-7425 · CVSS 7.8 HIGH · EPSS <1%

A flaw was found in libxslt where the attribute type, atype, flags are modified in a way that corrupts internal memory management. When XSLT functions, such as the key() process, result in tree fragments, this corruption prevents the proper cleanup of ID attributes. As a result, the system may access freed memory, causing crashes or enabling attackers to trigger heap corruption.

Is CVE-2025-7425 exploited?

Which products and versions are affected?

No affected package list recorded here yet.

Is there a patch?

No patch identifier recorded here yet.

What PlainSec published about CVE-2025-7425

Primary sources

What this record does not say

KEV and EPSS are re-checked daily. Record last updated 2026-08-15.