Junglewise Threat Intelligence

PYSEC-2023-296 - An XEE vulnerability has been found in Repox, which allows a remote attacker to interfere with the application's XML data processing in the

Severity: low · CVSS 3.1 · Published 2023-12-13

Technologies: repox (PyPI). Vendors: PyPI.

Executive brief

An XEE vulnerability has been found in Repox, which allows a remote attacker to interfere with the application's XML data processing in the fileupload function, resulting in interaction between the attacker and the server's file system.

Affected products

  • PyPI repox

Related threats