Stored Cross-Site Scripting Vulnerability in PySpector Framework by ParzivalHack
CVE-2026-33140
5.3MEDIUM
What is CVE-2026-33140?
The PySpector framework, designed for static analysis security testing in Python, contains a vulnerability in its HTML report generator. Versions up to and including 0.1.6 allow embedded JavaScript payloads to execute within the user's browser when a report is opened. This occurs as unfiltered code snippets are integrated into HTML reports, leading to potential cross-site scripting attacks. The vulnerability has been addressed in version 0.1.7, enhancing security in the report generation process.
Affected Version(s)
PySpector < 0.1.7
