VYPR
tags in string literals when producing JSON.","datePublished":"2017-09-06T21:29:00.473Z","dateModified":"2026-06-17T00:25:26.587Z","publisher":{"@type":"Organization","@id":"https://portal.vyprsec.ai#publisher","name":"VYPR","url":"https://portal.vyprsec.ai","logo":{"@type":"ImageObject","url":"https://portal.vyprsec.ai/icon.svg","width":64,"height":64},"description":"Real-time CVE intelligence newsroom — feeds, exploits, vendor advisories, and AI-synthesized insights."},"author":{"@type":"Organization","@id":"https://portal.vyprsec.ai#publisher","name":"VYPR","url":"https://portal.vyprsec.ai","logo":{"@type":"ImageObject","url":"https://portal.vyprsec.ai/icon.svg","width":64,"height":64},"description":"Real-time CVE intelligence newsroom — feeds, exploits, vendor advisories, and AI-synthesized insights."},"proficiencyLevel":"Expert","about":{"@type":"Thing","@id":"https://nvd.nist.gov/vuln/detail/CVE-2015-3161","name":"CVE-2015-3161","identifier":"CVE-2015-3161","description":"The search bar code in bkr/server/widgets.py in Beaker before 20.1 does not escape tags in string literals when producing JSON.","additionalType":"https://schema.org/SoftwareApplication","sameAs":["https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-3161"]},"keywords":"CVE-2015-3161, Medium, CWE-79, Beaker Beaker, Beaker Beaker","mentions":[{"@type":"SoftwareApplication","name":"Beaker","applicationCategory":"SecurityApplication","publisher":{"@type":"Organization","name":"Beaker"}},{"@type":"SoftwareApplication","name":"Beaker","applicationCategory":"SecurityApplication","publisher":{"@type":"Organization","name":"Beaker"}}],"isAccessibleForFree":true},{"@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://portal.vyprsec.ai/"},{"@type":"ListItem","position":2,"name":"CVEs","item":"https://portal.vyprsec.ai/cves"},{"@type":"ListItem","position":3,"name":"CVE-2015-3161","item":"https://portal.vyprsec.ai/cves/CVE-2015-3161"}]}]}
Medium severity4.8NVD Advisory· Published Sep 6, 2017· Updated Jun 17, 2026

CVE-2015-3161

CVE-2015-3161

Description

The search bar code in bkr/server/widgets.py in Beaker before 20.1 does not escape tags in string literals when producing JSON.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • Beaker/Beakerllm-create2 versions
    <20.1+ 1 more
    • (no CPE)range: <20.1
    • cpe:2.3:a:beaker-project:beaker:*:*:*:*:*:*:*:*range: <=20.0

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.