Safety vulnerability ID: 39194
The information on this page was manually curated by our Cybersecurity Intelligence Team.
Lxml 4.6.2 includes a fix for CVE-2020-27783: A XSS vulnerability was discovered in python-lxml's clean module. The module's parser didn't properly imitate browsers, which caused different behaviors between the sanitizer and the user's page. A remote attacker could exploit this flaw to run arbitrary HTML/JS code.
Latest version: 5.3.0
Powerful and Pythonic XML processing library combining libxml2/libxslt with the ElementTree API.
==================
Bugs fixed
----------
* A vulnerability (CVE-2020-27783) was discovered in the HTML Cleaner by Yaniv Nizry,
which allowed JavaScript to pass through. The cleaner now removes more sneaky
"style" content.
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application