VDB
Sign up
—

PYSEC-2022-256

Quick fix

PYSEC-2022-256 — deluge: upgrade to the fixed version with the command below.

pip install --upgrade 'deluge>=2.1.0'

Details

The Deluge Web-UI is vulnerable to XSS through a crafted torrent file. The the data from torrent files is not properly sanitised as it's interpreted directly as HTML. Someone who supplies the user with a malicious torrent file can execute arbitrary Javascript code in the context of the user's browser session.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/deluge
Introduced in: 0Fixed in: 2.1.0
Fixpip install --upgrade 'deluge>=2.1.0'

References