CVE-2026-49825
lxml: javascript: URL bypass in Cleaner via xlink:href
CVSS Score
8.2
EPSS Score
0.0%
EPSS Percentile
0th
lxml is a library for processing XML and HTML in the Python language. Prior to 6.1.1, link attributes in ``lxml.html.defs.link_attrs`` were missing ``xlink:href``, which can be used for URL bypass attacks in embedded SVG/MathML/etc. content. This vulnerability was fixed in lxml 6.1.1 and lxml_html_clean 0.4.5.
| CWE | CWE-79 CWE-184 |
| Vendor | lxml |
| Product | lxml |
| Published | Aug 20, 2026 |
Stay Ahead of the Next One
Get instant alerts for lxml lxml
Be the first to know when new high vulnerabilities affecting lxml lxml are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Changed
Confidentiality
High
Integrity
Low
Availability
None
Affected Versions
lxml / lxml
< 6.1.1
fedora-python / lxml_html_clean
< 0.4.5
References
github.com: https://github.com/fedora-python/lxml_html_clean/security/advisories/GHSA-4jhm-jv67-739f github.com: https://github.com/fedora-python/lxml_html_clean/commit/322357ac61c6cf80fcbaba53b4e92e31f3ded9f2 github.com: https://github.com/lxml/lxml/commit/5927a6d5e851845140975d99b65461e255caaab0 github.com: https://github.com/fedora-python/lxml_html_clean/releases/tag/0.4.5 github.com: https://github.com/lxml/lxml/releases/tag/lxml-6.1.1