—
PYSEC-2022-246
Quick fix
PYSEC-2022-246 — fava: upgrade to the fixed version with the command below.
pip install --upgrade 'fava>=68bbb6e39319deb35ab9f18d0b6aa9fa70472539'Details
Cross-site Scripting (XSS) - Reflected in GitHub repository beancount/fava prior to 1.22.3.
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/fava
Introduced in:
0Fixed in: 68bbb6e39319deb35ab9f18d0b6aa9fa70472539Fix
pip install --upgrade 'fava>=68bbb6e39319deb35ab9f18d0b6aa9fa70472539'