VDB
Sign up
MEDIUM6.1

PYSEC-2026-841

MapProxy vulnerable to cross-site scripting in demo service

Quick fix

PYSEC-2026-841 — mapproxy: upgrade to the fixed version with the command below.

pip install --upgrade 'mapproxy>=1.11.1'

Details

MapProxy version 1.11.1 and older are vulnerable to cross-site scripting in the demo service resulting in possible information disclosure. An incomplete fix was released in v[1.10.4](https://github.com/mapproxy/mapproxy/issues/322#issuecomment-518573169), and a complete fix was released in v[1.11.1](https://github.com/mapproxy/mapproxy/commit/436c8f489761d1b4ee22b2440b53cc96bbc28aea).

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/mapproxy
Introduced in: 0Fixed in: 1.11.1
Fixpip install --upgrade 'mapproxy>=1.11.1'

References