MEDIUM4.9
PYSEC-2026-1221
Biopython is vulnerable to doctype XML external entity (XXE) injection through Bio.Entrez
Quick fix
PYSEC-2026-1221 — biopython: upgrade to the fixed version with the command below.
pip install --upgrade 'biopython>=1.87'Details
Bio.Entrez in Biopython through 1.86 allows doctype XXE.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2025-68463[ADVISORY]
- https://github.com/biopython/biopython/issues/5109[WEB]
- https://github.com/biopython/biopython/commit/736c96f37b190732ecca9da80ad0cb9d4967214d[WEB]
- https://github.com/biopython/biopython[WEB]
- https://github.com/biopython/biopython/blob/master/NEWS.rst[WEB]
- https://pypi.org/project/biopython/1.87[WEB]
- http://www.openwall.com/lists/oss-security/2026/05/08/16[WEB]
- https://pypi.org/project/biopython[PACKAGE]
- https://github.com/advisories/GHSA-x3vf-39hj-gxr4[ADVISORY]