Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-9318

Опубликовано: 12 авг. 2026
Источник: redhat
CVSS3: 5.4
EPSS Низкий

Описание

tablib prior to 3.10.0 contains a stored cross-site scripting vulnerability in the HTML export functionality that allows attackers to execute arbitrary JavaScript by embedding malicious payloads in dataset titles, which are interpolated unsanitized into HTML output via the export_book method in the _html.py format handler. Attackers can rename worksheet sheets in imported files such as XLSX, ODS, XLS, or YAML with script payloads that are assigned to the Dataset title attribute and rendered unescaped inside an HTML h3 tag, leading to session hijacking, unauthorized administrative actions, and sensitive data exposure when the output is rendered in a browser.

A flaw was found in tablib. This vulnerability, a stored cross-site scripting (XSS) issue, allows a remote attacker to execute arbitrary JavaScript code. By embedding malicious payloads within dataset titles, which are not properly sanitized during HTML export, an attacker can trigger the execution of these scripts when the exported HTML is viewed in a browser. This could lead to consequences such as session hijacking, unauthorized administrative actions, and the exposure of sensitive data.

Отчет

This Moderate impact vulnerability in tablib's HTML export functionality allows for stored cross-site scripting. Exploitation requires an attacker to embed malicious JavaScript in dataset titles within imported files, which then executes when a user renders the exported HTML in a browser. Red Hat products that process untrusted data and utilize tablib for HTML export are affected, as this could lead to session hijacking or unauthorized actions.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Ansible Automation Platform 2ansible-automation-platform-24/hub-rhel8Fix deferred
Red Hat Ansible Automation Platform 2ansible-automation-platform-24/lightspeed-rhel8Fix deferred
Red Hat Ansible Automation Platform 2ansible-automation-platform-25/hub-rhel8Fix deferred
Red Hat Ansible Automation Platform 2ansible-automation-platform-25/lightspeed-rhel8Fix deferred
Red Hat Ansible Automation Platform 2ansible-automation-platform-26/hub-rhel9Fix deferred
Red Hat Ansible Automation Platform 2ansible-automation-platform-26/lightspeed-rhel9Fix deferred
Red Hat Ansible Automation Platform 2ansible-automation-platform-27/hub-rhel9Fix deferred
Red Hat Ansible Automation Platform 2ansible-automation-platform-27/lightspeed-rhel9Fix deferred
Red Hat Ansible Automation Platform 2python3.11-tablibFix deferred
Red Hat Ansible Automation Platform 2python3.12-tablibFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=2514468tablib: tablib: Arbitrary JavaScript execution via stored Cross-Site Scripting in HTML export

EPSS

Процентиль: 8%
0.00181
Низкий

5.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.4
ubuntu
около 1 месяца назад

tablib prior to 3.10.0 contains a stored cross-site scripting vulnerability in the HTML export functionality that allows attackers to execute arbitrary JavaScript by embedding malicious payloads in dataset titles, which are interpolated unsanitized into HTML output via the export_book method in the _html.py format handler. Attackers can rename worksheet sheets in imported files such as XLSX, ODS, XLS, or YAML with script payloads that are assigned to the Dataset title attribute and rendered unescaped inside an HTML h3 tag, leading to session hijacking, unauthorized administrative actions, and sensitive data exposure when the output is rendered in a browser.

CVSS3: 5.4
nvd
около 1 месяца назад

tablib prior to 3.10.0 contains a stored cross-site scripting vulnerability in the HTML export functionality that allows attackers to execute arbitrary JavaScript by embedding malicious payloads in dataset titles, which are interpolated unsanitized into HTML output via the export_book method in the _html.py format handler. Attackers can rename worksheet sheets in imported files such as XLSX, ODS, XLS, or YAML with script payloads that are assigned to the Dataset title attribute and rendered unescaped inside an HTML h3 tag, leading to session hijacking, unauthorized administrative actions, and sensitive data exposure when the output is rendered in a browser.

CVSS3: 5.4
debian
около 1 месяца назад

tablib prior to 3.10.0 contains a stored cross-site scripting vulnerab ...

CVSS3: 5.4
github
около 1 месяца назад

tablib: Stored XSS in the HTML export via unescaped dataset title

EPSS

Процентиль: 8%
0.00181
Низкий

5.4 Medium

CVSS3

Уязвимость CVE-2026-9318