Bug 2514468 (CVE-2026-9318)
| Summary: | CVE-2026-9318 tablib: tablib: Arbitrary JavaScript execution via stored Cross-Site Scripting in HTML export | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security DevOps Team <prodsec-dev> |
| Status: | NEW --- | QA Contact: | |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | unspecified | CC: | anthomas, dranck, dschmidt, ehelms, ggainey, jlanda, jmitchel, jpasqual, juwatts, jwong, kshier, lbrazdil, mdellweg, mhulan, mminar, nmoumoul, omaciel, osousa, pcreech, rbiba, rchan, simaishi, smallamp, sskracic, stcannon, teagle, tmalecek, tpfromme, ttakamiy, yguenane |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in tablib. This vulnerability, a stored cross-site scripting (XSS) issue, allows a remote attacker to execute arbitrary JavaScript code. By embedding malicious payloads within dataset titles, which are not properly sanitized during HTML export, an attacker can trigger the execution of these scripts when the exported HTML is viewed in a browser. This could lead to consequences such as session hijacking, unauthorized administrative actions, and the exposure of sensitive data.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 2514472, 2514473 | ||
| Bug Blocks: | |||
|
Description
OSIDB Bzimport
2026-08-12 02:41:52 UTC
|