Executive brief
PySpector is a Python code analysis tool that generates HTML reports highlighting code quality issues. A stored cross-site scripting vulnerability in the HTML report generator allows malicious JavaScript embedded in scanned Python files to execute in a user's browser when they open the generated report. An attacker could craft a malicious Python file, trick a user into scanning it, and then execute arbitrary JavaScript in their browser to manipulate content, redirect to phishing sites, or steal local files.
Technical details
PySpector versions ≤0.1.6 contain a stored XSS vulnerability (CWE-79) in the HTML report generator. When scanning a Python file containing JavaScript payloads (e.g., within string arguments to eval()), the flagged code snippet is interpolated into the generated HTML report without sanitization. The attack requires a user to scan an attacker-controlled Python file and open the resulting HTML report in a browser. While the file:// origin context limits exfiltration of credentials, an attacker can still achieve DOM manipulation, redirect attacks, and potential theft of locally accessible data via file:// fetch requests. The vulnerability has been patched in version 0.1.7.
Affected products
- PySpector PySpector ≤0.1.6
Timeline
- 2026-03-18: disclosed
- 2026-03-18: patched: Fixed in version 0.1.7