<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Simon Koeck | Security Writeups</title><description>Security vulnerability writeups, bug bounty reports, and research.</description><link>https://simonkoeck.com/</link><item><title>XXE Injection via Translation File Import in Tolgee</title><link>https://simonkoeck.com/writeups/tolgee-xxe-translation-import/</link><guid isPermaLink="true">https://simonkoeck.com/writeups/tolgee-xxe-translation-import/</guid><description>Tolgee&apos;s translation import parsers don&apos;t disable external entity processing, letting any user with import permissions read arbitrary files from the server and perform SSRF. Confirmed on the cloud platform.</description><pubDate>Tue, 07 Apr 2026 00:00:00 GMT</pubDate><category>xxe</category><category>xml</category><category>file-read</category><category>ssrf</category><category>tolgee</category><category>java</category></item></channel></rss>