HIGH8.8
PYSEC-2026-1842
pyspider Cross-Site Request Forgery (CSRF) via the Flask endpoints
Details
binux pyspider up to v0.3.10 was discovered to contain a Cross-Site Request Forgery (CSRF) via the Flask endpoints.
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/pyspider
Introduced in:
0No fixed version published yet for pyspider (pip). Pin to a known-safe version or switch to an alternative.
References
- https://nvd.nist.gov/vuln/detail/CVE-2024-39163[ADVISORY]
- https://github.com/binux/pyspider[PACKAGE]
- https://github.com/binux/pyspider/blob/master/pyspider/webui/debug.py#L39[WEB]
- https://www.sonarsource.com/blog/basic-http-authentication-risk-uncovering-pyspider-vulnerabilities[WEB]
- https://pypi.org/project/pyspider[PACKAGE]
- https://github.com/advisories/GHSA-pqj8-xhcx-prxm[ADVISORY]