HIGH8.2PyPI
GHSA-4jhm-jv67-739f· CVE-2026-49825, PYSEC-2026-2614`lxml_html_clean.Cleaner` does not strip `javascript:` URLs from namespaced URL attributes
Modified: 7/13/2026
package
pkg:pypi/lxml-html-clean
`lxml_html_clean.Cleaner` does not strip `javascript:` URLs from namespaced URL attributes
Modified: 7/13/2026
HTML Cleaner allows crafted scripts in special contexts like svg or math to pass through
Modified: 1/14/2025
lxml-html-clean has CSS @import Filter Bypass via Unicode Escapes
Modified: 9/10/2026
lxml-html-clean has <base> tag injection through default Cleaner configuration
Modified: 9/10/2026
Modified: 1/14/2025
Modified: 7/13/2026
Modified: 7/13/2026
`lxml_html_clean.Cleaner` does not strip `javascript:` URLs from namespaced URL attributes
Modified: 7/13/2026