Critical severity9.8NVD Advisory· Published Aug 16, 2021· Updated Jun 17, 2026
CVE-2020-18705
CVE-2020-18705
Description
XML External Entities (XXE) in Quokka v0.4.0 allows remote attackers to execute arbitrary code via the component 'quokka/core/content/views.py'.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
quokkaPyPI | <= 0.4.0 | — |
Affected products
3- cpe:2.3:a:quokka_project:quokka:0.4.0:*:*:*:*:*:*:*
- Quokka/Quokkadescription
Patches
Vulnerability mechanics
References
5- github.com/rochacbruno/quokka/issues/676nvdExploitPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-4q2r-qxp6-h5j6ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2020-18705ghsaADVISORY
- github.com/pypa/advisory-database/tree/main/vulns/quokka/PYSEC-2021-145.yamlghsaWEB
- github.com/quokkaproject/quokka/pull/679ghsaWEB
News mentions
0No linked articles in our index yet.