Advisory Database
  • Advisories
  • Dependency Scanning
  1. pypi
  2. ›
  3. slippers
  4. ›
  5. CVE-2026-34231

CVE-2026-34231: Slippers Vulnerable to Cross-Site Scripting (XSS) in `attrs` Template Tag

March 30, 2026 (updated March 31, 2026)

A Cross-site Scripting (XSS) vulnerability exists in the {% attrs %} template tag of the slippers Django package. When a context variable containing untrusted data is passed to {% attrs %}, the value is interpolated into an HTML attribute string without escaping, allowing an attacker to break out of the attribute context and inject arbitrary HTML or JavaScript into the rendered page.

References

  • github.com/advisories/GHSA-w7rv-gfp4-j9j3
  • github.com/mixxorz/slippers
  • github.com/mixxorz/slippers/commit/16cc4ef4fa8ad2f7aee30798f16c3e7b653423b2
  • github.com/mixxorz/slippers/releases/tag/0.6.3
  • github.com/mixxorz/slippers/security/advisories/GHSA-w7rv-gfp4-j9j3
  • nvd.nist.gov/vuln/detail/CVE-2026-34231

Code Behaviors & Features

Detect and mitigate CVE-2026-34231 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 0.6.3

Fixed versions

  • 0.6.3

Solution

Upgrade to version 0.6.3 or above.

Impact 6.1 MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Learn more about CVSS

Weakness

  • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Source file

pypi/slippers/CVE-2026-34231.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Sat, 09 May 2026 12:19:17 +0000.