A mutation XSS affects users calling bleach.clean with all of: svg or math in the allowed tags p or br in allowed tags style, title, noscript, script, textarea, noframes, iframe, or xmp in allowed tags the keyword argument strip_comments=False Note: none of the above tags are in the default allowed tags and strip_comments defaults to True.
CVSS Details
- CVSS 3.1 Base Score: 6.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade py3-bleach | Aug 22, 2024 | Feb 16, 2023 |
| Debian | — | Upgrade python-bleach | Apr 8, 2021 | Apr 8, 2021 |
| Suse | — | Upgrade python2-bleachUpgrade python3-bleach | Apr 15, 2021 | Apr 14, 2021 |
| Ubuntu | — | Upgrade python-bleach (Ubuntu Pro)Upgrade python-bleach-doc (Ubuntu Pro)Upgrade python3-bleach (Ubuntu Pro) | Mar 9, 2026 | Mar 5, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub