Impact
The flaw in pulp‑python’s PyPI simple index allows an attacker who can publish a package to inject arbitrary HTML markup into project names. When a user visits the index, the browser renders the unescaped markup, leading to cross‑site scripting that can execute scripts in the site’s origin. The impact is limited to the client side; no commands are run on the server. The vulnerability affects the simple index feature of the pulp‑python repository manager. All versions that expose the PyPI simple index without escaping project names are vulnerable, and no specific product version boundaries are identified in the advisory. The CVSS score of 5.4 indicates a moderate severity. With an unavailable EPSS and no listing in the CISA KEV catalog, exploitation is considered unlikely at the time of analysis, but the attack path is straightforward: publish a malicious package name and any visitor who loads the index will receive the injected markup, potentially enabling script execution within the visitor’s browser context.
Affected Systems
The vulnerability resides in the pulp‑python product, part of the Pulp repository management system, which provides a PyPI simple index for Python packages. All instances of pulp‑python that expose the simple index without escaping project names are considered affected. Separate version details are not supplied in the advisory.
Risk and Exploitability
The vulnerability is a moderate‑risk client‑side script execution flaw (CVSS 5.4). Because the attacker only needs the ability to publish a package, the required pre‑conditions are minimal. The flaw does not allow server compromise or remote code execution; it is limited to actions executed in the visitor’s browser for the duration of that session. The exploitation probability is currently unknown (no EPSS), and the issue is not listed in the CISA KEV catalog.
OpenCVE Enrichment