What problem does it solve?
XXE is a high-severity vulnerability that enables file read, SSRF, and RCE but is often missed during standard security assessments due to non-primary XML content types and hidden XML parsing in file uploads and SAML integrations. This Skill provides a complete, field-validated hunting framework to identify and exploit XXE flaws across modern tech stacks.
Core Features & Use Cases
- Comprehensive Attack Surface Mapping: Identifies XML entry points including REST/SOAP APIs, file upload features (SVG, DOCX, XLSX), SAML/SSO endpoints, and hidden XML parsing in JSON APIs.
- Pre-Built Payload & Bypass Library: Includes payloads for in-band file read, blind OOB exfiltration, SSRF pivots, and bypass techniques for WAFs, hardened parsers, egress filters, and content-type validation.
- Real-World Validation: Features 10 verified bug bounty case studies (Uber, Twitter, Adobe Commerce) and a parser ecosystem matrix to prioritize high-value targets and avoid wasting time on hardened parsers.
Use Case: A penetration tester assessing a SaaS platform with user file upload and SAML SSO can use this Skill to systematically test for XXE, bypass common defenses, and demonstrate critical impact with reproducible proof-of-concept payloads.
Quick Start
Use the hunt-xxe skill to test all XML-ingesting endpoints and file upload features on the authorized target for XXE vulnerabilities, including blind out-of-band and SSRF pivot chains.