CYBER CODE RED

Get real-time updates on Telegram

P4Verified

CVE-2026-9318: tablib 0 to before 3.10.0

CVE-2026-9318. CVSS 3.1 base score 5.4 (MEDIUM, Vendor/CNA). EPSS 0.00298 (percentile 0.2057), scored 2026-10-06.

Affected technology

tablib · 0 to before 3.10.0
Jazzband

Description’s affected range: prior to 3.10.0

Component: Not specified by the source

Attack conditions (Vendor/CNA, CVSS 4.0): Network (remote) · Low privileges required · Active user interaction

What an attacker can do

Attackers can rename worksheet sheets in imported files such as XLSX, ODS, XLS, or YAML with script payloads that are assigned to the Dataset title attribute and rendered unescaped inside an HTML h3 tag, leading to session hijacking, unauthorized administrative actions, and sensitive data exposure when the output is rendered in a browser. Vendor/CNA’s CVSS 4.0 assessment (base score 4.8/10) rates confidentiality and integrity impact as low; availability impact as none.

Published

CWE
CWE-79
CCR priority
21.7 /100 (P4)
CVSS 3.1
5.4 /10 · CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N · Vendor/CNA
EPSS
0.00298 · percentile 0.2065 · 2026-10-08
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2026-9318.html