High severity7.5NVD Advisory· Published Jun 29, 2023· Updated Jun 17, 2026
CVE-2020-26710
CVE-2020-26710
Description
easy-parse v0.1.1 was discovered to contain a XML External Entity Injection (XXE) vulnerability which allows attackers to execute arbitrary code via a crafted XML file.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
easy-parsePyPI | <= 0.1.1 | — |
Affected products
3- cpe:2.3:a:easy-parse_project:easy-parse:0.1.1:*:*:*:*:python:*:*
- easy-parse/easy-parsedescription
Patches
Vulnerability mechanics
References
4- github.com/advisories/GHSA-vv6q-6hwp-vrgpghsaADVISORY
- github.com/uncmath25/easy-parse/issues/3nvdIssue TrackingThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2020-26710ghsaADVISORY
- github.com/pypa/advisory-database/tree/main/vulns/easy-parse/PYSEC-2023-97.yamlghsaWEB
News mentions
0No linked articles in our index yet.