Skip to content

[GHSA-rqvm-6hhw-247j] XML Injection vulnerability in xmltodict allows Input...#7389

Closed
paagaard-t wants to merge 1 commit intopaagaard-t/advisory-improvement-7389from
paagaard-t-GHSA-rqvm-6hhw-247j
Closed

[GHSA-rqvm-6hhw-247j] XML Injection vulnerability in xmltodict allows Input...#7389
paagaard-t wants to merge 1 commit intopaagaard-t/advisory-improvement-7389from
paagaard-t-GHSA-rqvm-6hhw-247j

Conversation

@paagaard-t
Copy link
Copy Markdown

Updates

  • Affected products
  • CVSS v4
  • Description
  • Summary

Comments
it was missing

@github-actions github-actions bot changed the base branch from main to paagaard-t/advisory-improvement-7389 April 14, 2026 13:13
@shelbyc
Copy link
Copy Markdown
Contributor

shelbyc commented Apr 14, 2026

Hi @paagaard-t, as I mentioned at #6692 (comment), my teammates and I intentionally chose not to review this advisory due to disagreement about the validity of the underlying CVE. More information about the disagreement is available at martinblech/xmltodict#377.

@shelbyc shelbyc closed this Apr 14, 2026
@github-actions github-actions bot deleted the paagaard-t-GHSA-rqvm-6hhw-247j branch April 14, 2026 18:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants