Junglewise Threat Intelligence

CVE-2026-33140: PYSEC-2026-3029 - Stored XSS in PySpector HTML Report Generation leads to Javascript Code Execution

CVE-2026-33140 · Severity: medium · CVSS 4 · Published 2026-07-13

Technologies: Pyspector. Vendors: PyPI.

Executive brief

PySpector is a Python code analysis tool that generates HTML reports highlighting code quality issues. A stored cross-site scripting vulnerability in the HTML report generator allows malicious JavaScript embedded in scanned Python files to execute in a user's browser when they open the generated report. An attacker could craft a malicious Python file, trick a user into scanning it, and then execute arbitrary JavaScript in their browser to manipulate content, redirect to phishing sites, or steal local files.

Technical details

PySpector versions ≤0.1.6 contain a stored XSS vulnerability (CWE-79) in the HTML report generator. When scanning a Python file containing JavaScript payloads (e.g., within string arguments to eval()), the flagged code snippet is interpolated into the generated HTML report without sanitization. The attack requires a user to scan an attacker-controlled Python file and open the resulting HTML report in a browser. While the file:// origin context limits exfiltration of credentials, an attacker can still achieve DOM manipulation, redirect attacks, and potential theft of locally accessible data via file:// fetch requests. The vulnerability has been patched in version 0.1.7.

Affected products

  • PySpector PySpector ≤0.1.6

Timeline

  • 2026-03-18: disclosed
  • 2026-03-18: patched: Fixed in version 0.1.7

References

Related threats