{"id":"CVE-2020-27783","aliases":["GHSA-pgww-xf46-h92r","PYSEC-2020-62"],"url":"https://o3.security/vulnerability/CVE-2020-27783","summary":"lxml vulnerable to Cross-site Scripting","details":"A XSS vulnerability was discovered in python-lxml's clean module. The module's parser didn't properly imitate browsers, which caused different behaviors between the sanitizer and the user's page. A remote attacker could exploit this flaw to run arbitrary HTML/JS code.","published":"2020-12-03T17:15:13.177Z","modified":"2026-07-08T05:56:38.709389927Z","cvss":{"score":6.1,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"},"epss":{"score":0.03934,"percentile":0.89601,"asOf":"2026-08-23"},"cisaKev":null,"exploitsKnown":2,"affectedPackages":[{"ecosystem":"PyPI","name":"lxml","fixedVersion":"4.6.2"}],"fix":null,"references":[{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JKG67GPGTV23KADT4D4GK4RMHSO4CIQL/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TMHVKRUT22LVWNL3TB7HPSDHJT74Q3JK/"},{"type":"ADVISORY","url":"https://lists.debian.org/debian-lts-announce/2020/12/msg00028.html"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20210521-0003/"},{"type":"ADVISORY","url":"https://www.debian.org/security/2020/dsa-4810"},{"type":"FIX","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1901633"},{"type":"FIX","url":"https://www.oracle.com//security-alerts/cpujul2021.html"},{"type":"EVIDENCE","url":"https://advisory.checkmarx.net/advisory/CX-2020-4286"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T05:56:38.709389927Z"}}