MEDIUM5.4
PYSEC-2026-910
pyRdfa3 Cross-site Scripting vulnerability
Quick fix
PYSEC-2026-910 — pyrdfa3: upgrade to the fixed version with the command below.
pip install --upgrade 'pyrdfa3>=3.6.2'Details
A vulnerability was found in RDFlib pyrdfa3 and classified as problematic. This issue affects the function `_get_option` of the file `pyRdfa/__init__.py`. The manipulation leads to cross site scripting. The attack may be initiated remotely. The name of the patch is ffd1d62dd50d5f4190013b39cedcdfbd81f3ce3e. It is recommended to apply a patch to fix this issue. The identifier VDB-215249 was assigned to this vulnerability.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2022-4396[ADVISORY]
- https://github.com/RDFLib/pyrdfa3/issues/38[WEB]
- https://github.com/RDFLib/pyrdfa3/pull/40[WEB]
- https://github.com/RDFLib/pyrdfa3/commit/ffd1d62dd50d5f4190013b39cedcdfbd81f3ce3e[WEB]
- https://github.com/RDFLib/pyrdfa3[PACKAGE]
- https://vuldb.com/?id.215249[WEB]
- https://pypi.org/project/pyrdfa3[PACKAGE]
- https://github.com/advisories/GHSA-894q-wpg5-mf2h[ADVISORY]