—
PYSEC-2022-240
Quick fix
PYSEC-2022-240 — fava: upgrade to the fixed version with the command below.
pip install --upgrade 'fava>=dccfb6a2f4567f35ce2e9a78e24f92ebf946bc9b'Details
Cross-site Scripting (XSS) - Reflected in GitHub repository beancount/fava prior to 1.22.2.
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/fava
Introduced in:
0Fixed in: dccfb6a2f4567f35ce2e9a78e24f92ebf946bc9bFix
pip install --upgrade 'fava>=dccfb6a2f4567f35ce2e9a78e24f92ebf946bc9b'