Incomplete List of Disallowed Inputs Affecting lxml-html-clean package, versions [,0.4.5)


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

Social Trends

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-PYTHON-LXMLHTMLCLEAN-17911675
  • published9 Jul 2026
  • disclosed8 Jul 2026
  • creditglefait

Introduced: 8 Jul 2026

CVE-2026-49825  (opens in a new tab)
CWE-184  (opens in a new tab)
CWE-79  (opens in a new tab)

How to fix?

Upgrade lxml-html-clean to version 0.4.5 or higher.

Overview

lxml-html-clean is a HTML cleaner from lxml project

Affected versions of this package are vulnerable to Incomplete List of Disallowed Inputs in the Cleaner process when handling namespaced URL attributes such as xlink:href with the safe_attrs_only=False configuration. An attacker can execute arbitrary JavaScript in the context of the victim's browser by injecting payloads containing javascript: URLs in SVG or MathML elements, which are not properly sanitized. This is only exploitable if the safe_attrs_only option is explicitly set to False.

References

CVSS Base Scores

version 4.0
version 3.1