VDB
Sign up
—

PYSEC-2020-62

Quick fix

PYSEC-2020-62 — lxml: upgrade to the fixed version with the command below.

pip install --upgrade 'lxml>=4.6.2'

Details

A XSS vulnerability was discovered in python-lxml's clean module. The module's parser didn't properly imitate browsers, which caused different behaviors between the sanitizer and the user's page. A remote attacker could exploit this flaw to run arbitrary HTML/JS code.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/lxml
Introduced in: 1.2Fixed in: 4.6.2
Fixpip install --upgrade 'lxml>=4.6.2'

References