Description
A flaw was found in pulp-python's PyPI simple index. Project names are written into the HTML index without escaping. A user who can publish a Python package can store markup in the package name. A person who opens that index in a browser runs the markup in the origin that served the page, and the attacker or user can take limited actions as that person on that site during the visit. The flaw does not run commands on the server.
Published: n/a
Score: 5.4 Medium
EPSS: n/a
KEV: No
Impact: Client‑Side Script Execution (XSS)
Action: Apply Patch
AI Analysis

Impact

The flaw in pulp‑python’s PyPI simple index allows an attacker who can publish a package to inject arbitrary HTML markup into project names. When a user visits the index, the browser renders the unescaped markup, leading to cross‑site scripting that can execute scripts in the site’s origin. The impact is limited to the client side; no commands are run on the server. The vulnerability affects the simple index feature of the pulp‑python repository manager. All versions that expose the PyPI simple index without escaping project names are vulnerable, and no specific product version boundaries are identified in the advisory. The CVSS score of 5.4 indicates a moderate severity. With an unavailable EPSS and no listing in the CISA KEV catalog, exploitation is considered unlikely at the time of analysis, but the attack path is straightforward: publish a malicious package name and any visitor who loads the index will receive the injected markup, potentially enabling script execution within the visitor’s browser context.

Affected Systems

The vulnerability resides in the pulp‑python product, part of the Pulp repository management system, which provides a PyPI simple index for Python packages. All instances of pulp‑python that expose the simple index without escaping project names are considered affected. Separate version details are not supplied in the advisory.

Risk and Exploitability

The vulnerability is a moderate‑risk client‑side script execution flaw (CVSS 5.4). Because the attacker only needs the ability to publish a package, the required pre‑conditions are minimal. The flaw does not allow server compromise or remote code execution; it is limited to actions executed in the visitor’s browser for the duration of that session. The exploitation probability is currently unknown (no EPSS), and the issue is not listed in the CISA KEV catalog.

Generated by OpenCVE AI on October 7, 2026 at 13:20 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade pulp‑python to a release that escapes project names in the simple index.
  • Disable or restrict access to the PyPI simple index for unauthenticated or untrusted users until a fix is available.
  • Validate or sanitize package names on publish to strip or escape HTML markup before storing them.

Generated by OpenCVE AI on October 7, 2026 at 13:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 12:30:00 +0000

Type Values Removed Values Added
Description A flaw was found in pulp-python's PyPI simple index. Project names are written into the HTML index without escaping. A user who can publish a Python package can store markup in the package name. A person who opens that index in a browser runs the markup in the origin that served the page, and the attacker or user can take limited actions as that person on that site during the visit. The flaw does not run commands on the server.
Title pulp_python: Simple index renders project names without HTML escaping
Weaknesses CWE-79
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}

threat_severity

Moderate


Subscriptions

No data.

cve-icon MITRE

No data.

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-10-07T05:34:00Z

Links: CVE-2026-103871 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T13:30:17Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')