Stored Cross-Site Scripting Vulnerability in PySpector Framework by ParzivalHack
CVE-2026-33140

5.3MEDIUM

Key Information:

Status
Vendor
CVE Published:
20 March 2026

What is CVE-2026-33140?

The PySpector framework, designed for static analysis security testing in Python, contains a vulnerability in its HTML report generator. Versions up to and including 0.1.6 allow embedded JavaScript payloads to execute within the user's browser when a report is opened. This occurs as unfiltered code snippets are integrated into HTML reports, leading to potential cross-site scripting attacks. The vulnerability has been addressed in version 0.1.7, enhancing security in the report generation process.

Affected Version(s)

PySpector < 0.1.7

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.