Skip to main content

AGENTFORCE-25.5: Unsafe XML / SSRF via Dom.Document

๐Ÿ”ด High ยท XXE / SSRF

Detects Apex that fetches a remote URL and parses it with Dom.Document / getBodyDocument, enabling SSRF and XXE-style attacks when the URL is attacker-controlled.

Detailsโ€‹

FieldValue
Rule IDAGENTFORCE-25.5
SeverityHigh
CategoryXXE / SSRF

Remediationโ€‹

Allowlist destinations, never pass user input to setEndpoint, and avoid parsing untrusted XML with Dom.Document.

See Alsoโ€‹