VDB
Sign up
MEDIUM5.4

PYSEC-2026-1501

Koji Cross-site Scripting

Quick fix

PYSEC-2026-1501 — koji: upgrade to the fixed version with the command below.

pip install --upgrade 'koji>=1.33.2'

Details

A vulnerability in Koji was found. An unsanitized input allows for an XSS attack. Javascript code from a malicious link could be reflected in the resulting web page. It is not expected to be able to submit an action or make a change in Koji due to existing XSS protections in the code.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/koji
Introduced in: 0Fixed in: 1.33.2
Fixpip install --upgrade 'koji>=1.33.2'

References