VYPR
Medium severity5.4NVD Advisory· Published Dec 24, 2024· Updated Apr 15, 2026

CVE-2024-9427

CVE-2024-9427

Description

A vulnerability in Koji was found. An unsanitized input allows for an XSS attack. Javascript code from a malicious link could be reflected in the resulting web page. It is not expected to be able to submit an action or make a change in Koji due to existing XSS protections in the code

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
kojiPyPI
>= 1.35.0, < 1.35.11.35.1
kojiPyPI
>= 1.34.0, < 1.34.31.34.3
kojiPyPI
< 1.33.21.33.2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

7

News mentions

0

No linked articles in our index yet.