MEDIUM6.1
PYSEC-2026-1356
FastAPI Admin cross-site scripting (XSS) vulnerability in the Create Product function
Details
A cross-site scripting (XSS) vulnerability in the Create Product function of fastapi-admin pro v0.1.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Product Name parameter.
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/fastapi-admin
Introduced in:
0No fixed version published yet for fastapi-admin (pip). Pin to a known-safe version or switch to an alternative.
References
- https://nvd.nist.gov/vuln/detail/CVE-2024-42816[ADVISORY]
- https://github.com/fastapi-admin/fastapi-admin/issues/172[WEB]
- https://fastapi-admin-pro.long2ice.io/admin/login[WEB]
- https://github.com/fastapi-admin/fastapi-admin[PACKAGE]
- https://pypi.org/project/fastapi-admin[PACKAGE]
- https://github.com/advisories/GHSA-22xm-w7r2-834q[ADVISORY]