AGENTFORCE-25.5: Unsafe XML / SSRF via Dom.Document
๐ด High ยท XXE / SSRF
Detects Apex that fetches a remote URL and parses it with Dom.Document / getBodyDocument, enabling SSRF and XXE-style attacks when the URL is attacker-controlled.
Detailsโ
| Field | Value |
|---|---|
| Rule ID | AGENTFORCE-25.5 |
| Severity | High |
| Category | XXE / SSRF |
Remediationโ
Allowlist destinations, never pass user input to setEndpoint, and avoid parsing untrusted XML with Dom.Document.