Description
A flaw was found in pulp-python's PyPI simple index. Project names are written into the HTML index without escaping. A user who can publish a Python package can store markup in the package name. A person who opens that index in a browser runs the markup in the origin that served the page, and the attacker or user can take limited actions as that person on that site during the visit. The flaw does not run commands on the server.
Published: n/a
Score: 5.4 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 12:30:00 +0000

Type Values Removed Values Added
Description A flaw was found in pulp-python's PyPI simple index. Project names are written into the HTML index without escaping. A user who can publish a Python package can store markup in the package name. A person who opens that index in a browser runs the markup in the origin that served the page, and the attacker or user can take limited actions as that person on that site during the visit. The flaw does not run commands on the server.
Title pulp_python: Simple index renders project names without HTML escaping
Weaknesses CWE-79
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}

threat_severity

Moderate


Subscriptions

No data.

cve-icon MITRE

No data.

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-10-07T05:34:00Z

Links: CVE-2026-103871 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T13:30:17Z

Weaknesses