VDB
Sign up
MEDIUM6.1

PYSEC-2026-913

Review Board Cross-site scripting (XSS) vulnerability in the reviews dropdown

Quick fix

PYSEC-2026-913 — reviewboard: upgrade to the fixed version with the command below.

pip install --upgrade 'reviewboard>=1.6.17'

Details

Cross-site scripting (XSS) vulnerability in the auto-complete widget in htdocs/media/rb/js/reviews.js in Review Board 1.6.x before 1.6.17 and 1.7.x before 1.7.10 allows remote attackers to inject arbitrary web script or HTML via a full name.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/reviewboard
Introduced in: 1.6Fixed in: 1.6.17
Fixpip install --upgrade 'reviewboard>=1.6.17'

References