Stored Cross-Site Scripting Vulnerability in Tablib by Jazzband
CVE-2026-9318

4.8MEDIUM

Key Information:

Vendor

Jazzband

Status
Vendor
CVE Published:
12 August 2026

What is CVE-2026-9318?

Tablib versions prior to 3.10.0 have a stored cross-site scripting vulnerability in the HTML export functionality, allowing attackers to embed malicious JavaScript in dataset titles. This is executed unsanitized through the export_book method in the _html.py format handler. By renaming worksheets in imported files such as XLSX, ODS, XLS, or YAML, attackers can introduce script payloads that render unescaped inside HTML tags, potentially leading to session hijacking, unauthorized administrative actions, and sensitive data exposure when the output is viewed in a browser.

Affected Version(s)

tablib 0

References

CVSS V4

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Katriel Moses
.