VDB
Sign up
—

PYSEC-2026-667

MoinMoin Cross-site scripting (XSS) vulnerability

Quick fix

PYSEC-2026-667 — moin: upgrade to the fixed version with the command below.

pip install --upgrade 'moin>=1.6.1'

Details

Cross-site scripting (XSS) vulnerability in MoinMoin 1.5.x through 1.5.8 and 1.6.x before 1.6.1 allows remote attackers to inject arbitrary web script or HTML via the login action.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/moin
Introduced in: 1.5Fixed in: 1.6.1
Fixpip install --upgrade 'moin>=1.6.1'

References