VDB
Sign up
—

PYSEC-2017-14

Quick fix

PYSEC-2017-14 — html5lib: upgrade to the fixed version with the command below.

pip install --upgrade 'html5lib>=9b8d8eb5afbc066b7fac9390f5ec75e5e8a7cab7'

Details

The serializer in html5lib before 0.99999999 might allow remote attackers to conduct cross-site scripting (XSS) attacks by leveraging mishandling of the < (less than) character in attribute values.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/html5lib
Introduced in: 0Fixed in: 9b8d8eb5afbc066b7fac9390f5ec75e5e8a7cab7
Fixpip install --upgrade 'html5lib>=9b8d8eb5afbc066b7fac9390f5ec75e5e8a7cab7'

References