A mutation XSS affects users calling bleach.clean with all of: svg or math in the allowed tags p or br in allowed tags style, title, noscript, script, textarea, noframes, iframe, or xmp in allowed tags the keyword argument strip_comments=False Note: none of the above tags are in the default allowed tags and strip_comments defaults to True.
CVSS Details
- CVSS 3.1 Base Score: 6.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | alpine-linux-upgrade-py3-bleach | Aug 22, 2024 | Feb 16, 2023 | |
| Debian | debian-upgrade-python-bleach | Apr 8, 2021 | Apr 8, 2021 | |
| Suse | — | suse-upgrade-python2-bleachsuse-upgrade-python3-bleach | Apr 15, 2021 | Apr 14, 2021 |
| Ubuntu | ubuntu-pro-upgrade-python-bleachubuntu-pro-upgrade-python-bleach-docubuntu-pro-upgrade-python3-bleach | Mar 9, 2026 | Mar 5, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub