Junglewise Threat Intelligence

CVE-2024-37063: PYSEC-2026-2060 - ydata cross-site scripting

CVE-2024-37063 · Severity: low · CVSS 3.1 · Published 2026-07-07

Technologies: Ydata-Profiling. Vendors: PyPI.

Executive brief

Ydata's ydata-profiling library is a data analysis tool that generates HTML reports for exploring Pandas and Spark DataFrames. A cross-site scripting (XSS) vulnerability allows attackers to inject and execute malicious JavaScript code when users view a crafted report in their browser, potentially enabling account compromise, data theft, or malware distribution.

Technical details

The vulnerability is a DOM-based or stored XSS flaw (CWE-79) in ydata-profiling versions 3.7.0 through 4.8.3 that fails to properly sanitize user-controlled or malicious input when generating HTML reports. An attacker can craft a malicious report file that, when viewed in a browser, executes arbitrary JavaScript code with the privileges of the user viewing the report. The attack requires user interaction (opening the report) and local or adjacent network access to deliver the malicious file. The impact includes confidentiality, integrity, and availability compromise. A patch is expected in versions after 4.8.3.

Affected products

  • Ydata ydata-profiling 3.7.0 through 4.8.3

Timeline

  • 2024-06-04: disclosed
  • 2024-06-05: advisory: GitHub security review completed

References

Related threats