VDB
Sign up
—

PYSEC-2020-111

Quick fix

PYSEC-2020-111 — svglib: upgrade to the fixed version with the command below.

pip install --upgrade 'svglib>=0.9.4'

Details

The svglib package through 0.9.3 for Python allows XXE attacks via an svg2rlg call.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/svglib
Introduced in: 0Fixed in: 0.9.4
Fixpip install --upgrade 'svglib>=0.9.4'

References