CVE-2023-27494
Published on: Not Yet Published
Last Modified on: 03/17/2023 04:04:00 AM UTC
Certain versions of Streamlit from Streamlit contain the following vulnerability:
Streamlit, software for turning data scripts into web applications, had a cross-site scripting (XSS) vulnerability in versions 0.63.0 through 0.80.0. Users of hosted Streamlit app(s) were vulnerable to a reflected XSS vulnerability. An attacker could craft a malicious URL with Javascript payloads to a Streamlit app. The attacker could then trick the user into visiting the malicious URL and, if successful, the server would render the malicious javascript payload as-is, leading to XSS. Version 0.81.0 contains a patch for this vulnerability.
- CVE-2023-27494 has been assigned by
[email protected] to track the vulnerability
- Affected Vendor/Software:
streamlit - streamlit version = >= 0.63.0, < 0.81.0
CVE References
Description | Tags ⓘ | Link |
---|---|---|
Remove path from 404 response (#3165) · streamlit/[email protected] · GitHub | github.com text/html |
![]() |
Streamlit publishes previously-patched XSS vulnerability · Advisory · streamlit/streamlit · GitHub | github.com text/html |
![]() |
There are currently no QIDs associated with this CVE
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2023-27494 : Streamlit, software for turning data scripts into web applications, had a cross-site scripting… twitter.com/i/web/status/1… | 2023-03-16 21:11:09 |
![]() |
CVE-2023-27494 | 2023-03-16 21:38:54 |