CVE-2026-33913
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, an authenticated user with access to the Carecoordination module can upload a crafted CCDA document containing xi:include href="file:///etc/passwd" parse="text"/ to read arbitrary files from the server. Version 8.0.0.3 patches the issue.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/33xxx/CVE-2026-33913.json, https://github.com/openemr/openemr/commit/67e1702c41cf486af0069bdafce19860e2cd9a11, https://github.com/openemr/openemr/releases/tag/v800_3, https://github.com/openemr/openemr/security/advisories/GHSA-9757-3cfj-wc8q, https://nvd.nist.gov/vuln/detail/CVE-2026-33913
