martinblech/xmltodict

martinblech/xmltodict

Releases40
Frequency4 months 4 days
Last Release
Stars5.74K
Python module that makes working with XML feel like you are working with JSON

CVE History

CVEPublishedCVSS v3CVSS v2

XML Injection vulnerability in xmltodict allows Input Data Manipulation. This issue affects xmltodict: from 0.14.2 before 0.15.1. NOTE: the scope of this CVE is disputed by the vendor on the grounds that xmltodict.unparse() delegates element-name handling to Python's xml.sax.saxutils.XMLGenerator, and that XMLGenerator should be the component performing validation.