{"id":"CVE-2017-5992","aliases":["GHSA-chqf-hx79-gxc6","PYSEC-2017-48"],"url":"https://o3.security/vulnerability/CVE-2017-5992","summary":"Improper Restriction of XML External Entity Reference in Openpyxl","details":"Openpyxl 2.4.1 resolves external entities by default, which allows remote attackers to conduct XXE attacks via a crafted .xlsx document.","published":"2017-02-15T19:59:01.283Z","modified":"2026-03-14T09:25:26.251809Z","cvss":{"score":8.2,"severity":"HIGH","vector":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"openpyxl","fixedVersion":"2.4.2"}],"fix":null,"references":[{"type":"ADVISORY","url":"http://www.openwall.com/lists/oss-security/2017/02/07/5"},{"type":"REPORT","url":"https://bitbucket.org/openpyxl/openpyxl/commits/3b4905f428e1"},{"type":"REPORT","url":"https://bitbucket.org/openpyxl/openpyxl/issues/749"},{"type":"REPORT","url":"https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=854442"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-03-14T09:25:26.251809Z"}}