CVE-2025-29925 | xwiki-platform up to 15.10.13/16.4.5/16.9.x REST Endpoint pages transmission of private resources into a new sphere ('resource leak') (GHSA-22q5-9phm-744v)
A vulnerability, which was classified as problematic, has been found in xwiki-platform up to 15.10.13/16.4.5/16.9.x. This issue affects some unknown processing of the file /rest/wikis/[wikiName]/pages of the component REST Endpoint. The manipulation leads to transmission of private resources into a new sphere ('resource leak').
The identification of this vulnerability is CVE-2025-29925. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.