Description
This module validates CVE-2025-54988 / CVE-2025-66516 through an Elasticsearch ingest pipeline using the attachment processor. It creates a temporary pipeline, submits an in-memory PDF containing crafted XFA data to the _simulate API, extracts a caller-selected local file, and removes the pipeline in an ensure block.
The target must permit pipeline creation, simulation, and deletion. The default proof file is /etc/hostname. No index or document is created.
Module options
To display the available options, load the module within the Metasploit console and run the commands 'show options' or 'show advanced':
msf > use auxiliary/scanner/http/elasticsearch/tika_xfa_xxemsf undefined(tika_xfa_xxe) > show actions ...actions...msf undefined(tika_xfa_xxe) > set ACTION < action-name >msf undefined(tika_xfa_xxe) > show options ...show and set options...msf undefined(tika_xfa_xxe) > runPrioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub