Known Vulnerable Dependency: lxml — 10 advisory(ies): CVE-2021-43818 (lxml's HTML Cleaner allows crafted and SVG embedded scripts to pass through); CVE-2014-3146 (lxml Cross-site Scripting Via Control Characters); CVE-2021-28957 (lxml vulnerable to Cross-Site Scripting ) +7 more
High
- Category
- Supply Chain
- Confidence
- 91% confidence
- Finding
- The requirement permits installing lxml versions affected by known security advisories, and this skill processes imported document content where XML/HTML parsing is security-relevant. In a presentation-generation workflow that may ingest external files, vulnerable parser behavior can enable XSS-like sanitization bypasses, parser abuse, or other downstream document-processing attacks depending on how lxml is used.
