Stored Cross-Site Scripting Vulnerability in Tablib by Jazzband
CVE-2026-9318
4.8MEDIUM
What is CVE-2026-9318?
Tablib versions prior to 3.10.0 have a stored cross-site scripting vulnerability in the HTML export functionality, allowing attackers to embed malicious JavaScript in dataset titles. This is executed unsanitized through the export_book method in the _html.py format handler. By renaming worksheets in imported files such as XLSX, ODS, XLS, or YAML, attackers can introduce script payloads that render unescaped inside HTML tags, potentially leading to session hijacking, unauthorized administrative actions, and sensitive data exposure when the output is viewed in a browser.
Affected Version(s)
tablib 0
