VYPR
High severity8.2NVD Advisory· Published Aug 20, 2026· Updated Sep 18, 2026

CVE-2026-49825

CVE-2026-49825

Description

lxml is a library for processing XML and HTML in the Python language. Prior to 6.1.1, link attributes in `lxml.html.defs.link_attrs were missing xlink:href`, which can be used for URL bypass attacks in embedded SVG/MathML/etc. content. This vulnerability was fixed in lxml 6.1.1 and lxml_html_clean 0.4.5.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
lxml_html_cleanPyPI
< 0.4.50.4.5

Affected products

6

Patches

Vulnerability mechanics

References

6

News mentions

0

No linked articles in our index yet.