VDB
Sign up
—

PYSEC-2026-625

Cross-site Scripting in Ericsson CodeChecker

Quick fix

PYSEC-2026-625 — codechecker: upgrade to the fixed version with the command below.

pip install --upgrade 'codechecker>=6.18.2'

Details

In Ericsson CodeChecker prior to 6.18.2, a Stored Cross-site scripting (XSS) vulnerability in the comments component of the reports viewer allows remote attackers to inject arbitrary web script or HTML via the POST JSON data of the /CodeCheckerService API.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/codechecker
Introduced in: 0Fixed in: 6.18.2
Fixpip install --upgrade 'codechecker>=6.18.2'

References