MEDIUM6.1
PYSEC-2026-1843
pyspider Cross-site Scripting vulnerability
Details
pyspider through 0.3.10 allows /update XSS. NOTE: This vulnerability only affects products that are no longer supported by the maintainer
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/pyspider
Introduced in:
0No fixed version published yet for pyspider (pip). Pin to a known-safe version or switch to an alternative.
References
- https://nvd.nist.gov/vuln/detail/CVE-2024-39162[ADVISORY]
- https://docs.pyspider.org/en/latest[WEB]
- https://github.com/binux/pyspider[PACKAGE]
- https://www.sonarsource.com/blog/basic-http-authentication-risk-uncovering-pyspider-vulnerabilities[WEB]
- https://pypi.org/project/pyspider[PACKAGE]
- https://github.com/advisories/GHSA-x4x5-jx9j-mmv7[ADVISORY]