What is CVE-2026-9318?
CVE-2026-9318 is a stored cross-site scripting vulnerability in the HTML export functionality of tablib prior to version 3.10.0. Attackers can execute arbitrary JavaScript by injecting malicious payloads into dataset titles, which are unsanitized in the HTML output produced by the export_book method. Affected users should immediately update tablib to version 3.10.0 or later.
Azərbaycanca: CVE-2026-9318, tablib kitabxanasının 3.10.0 versiyasından əvvəlki versiyalarında HTML ixrac (export) funksionallığında aşkarlanmış Stored XSS zəifliyidir. Təcavüzkarlar dataset başlıqlarına zərərli JavaScript yükləyərək ixrac nəticəsində onların icra olunmasına nail ola bilərlər. Təsirə məruz qalan istifadəçilər dərhal tablib-i 3.10.0 və ya daha yuxarı versiyaya yeniləməlidirlər.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which versions of tablib are affected by CVE-2026-9318?
CVE-2026-9318 affects all versions of the tablib library prior to version 3.10.0.
How can users protect themselves against CVE-2026-9318?
Users should immediately update the tablib library to version 3.10.0 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.