{"id":"CVE-2020-29128","aliases":["GHSA-69q2-p9xp-739v","GHSA-f5gc-p5m3-v347","PYSEC-2020-75"],"url":"https://o3.security/vulnerability/CVE-2020-29128","summary":"Duplicate Advisory: XML Injection in petl","details":"petl before 1.68, in some configurations, allows resolution of entities in an XML document.","published":"2020-11-26T05:15:10.470Z","modified":"2026-07-09T01:06:17.758552Z","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"PyPI","name":"petl","fixedVersion":"1.6.8"}],"fix":{"url":"https://github.com/petl-developers/petl/pull/527","label":"petl-developers/petl#527"},"references":[{"type":"ADVISORY","url":"https://github.com/nvn1729/advisories/blob/master/cve-2020-29128.md"},{"type":"ADVISORY","url":"https://github.com/petl-developers/petl/security/advisories/GHSA-f5gc-p5m3-v347"},{"type":"ADVISORY","url":"https://petl.readthedocs.io/en/stable/changes.html"},{"type":"REPORT","url":"https://github.com/petl-developers/petl/issues/526"},{"type":"FIX","url":"https://github.com/petl-developers/petl/compare/v1.6.7...v1.6.8"},{"type":"FIX","url":"https://github.com/petl-developers/petl/pull/527"},{"type":"FIX","url":"https://github.com/petl-developers/petl/pull/527/commits/1b0a09f08c3cdfe2e69647bd02f97c1367a5b5f8"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-09T01:06:17.758552Z"}}