{"id":"CVE-2018-19787","aliases":["GHSA-xp26-p53h-6h2p","PYSEC-2018-12"],"url":"https://o3.security/vulnerability/CVE-2018-19787","summary":"Improper Neutralization of Input During Web Page Generation in LXML","details":"An issue was discovered in lxml before 4.2.5. lxml/html/clean.py in the lxml.html.clean module does not remove javascript: URLs that use escaping, allowing a remote attacker to conduct XSS attacks, as demonstrated by \"j a v a s c r i p t:\" in Internet Explorer. This is a similar issue to CVE-2014-3146.","published":"2018-12-02T10:29:00.227Z","modified":"2026-07-08T05:52:30.879010403Z","cvss":{"score":6.1,"severity":"MEDIUM","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"},"epss":{"score":0.02438,"percentile":0.83499,"asOf":"2026-09-17"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"lxml","fixedVersion":"4.2.5"}],"fix":{"url":"https://github.com/lxml/lxml/commit/6be1d081b49c97cfd7b3fbd934a193b668629109","label":"lxml/lxml@6be1d08"},"references":[{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2020/11/msg00044.html"},{"type":"ADVISORY","url":"https://lists.debian.org/debian-lts-announce/2018/12/msg00001.html"},{"type":"ADVISORY","url":"https://usn.ubuntu.com/3841-1/"},{"type":"ADVISORY","url":"https://usn.ubuntu.com/3841-2/"},{"type":"FIX","url":"https://github.com/lxml/lxml/commit/6be1d081b49c97cfd7b3fbd934a193b668629109"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T05:52:30.879010403Z"}}