Get real-time updates on Telegram
CVE-2026-9318: tablib 0 to before 3.10.0
CVE-2026-9318. CVSS 3.1 base score 5.4 (MEDIUM, Vendor/CNA). EPSS 0.00298 (percentile 0.2057), scored 2026-10-06.
Affected technology
tablib · 0 to before 3.10.0
Jazzband
Description’s affected range: prior to 3.10.0
Component: Not specified by the source
Attack conditions (Vendor/CNA, CVSS 4.0): Network (remote) · Low privileges required · Active user interaction
What an attacker can do
Attackers can rename worksheet sheets in imported files such as XLSX, ODS, XLS, or YAML with script payloads that are assigned to the Dataset title attribute and rendered unescaped inside an HTML h3 tag, leading to session hijacking, unauthorized administrative actions, and sensitive data exposure when the output is rendered in a browser. Vendor/CNA’s CVSS 4.0 assessment (base score 4.8/10) rates confidentiality and integrity impact as low; availability impact as none.
- CWE
- CWE-79
- CCR priority
- 21.7 /100 (P4)
- CVSS 3.1
- 5.4 /10 · CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N · Vendor/CNA
- EPSS
- 0.00298 · percentile 0.2065 · 2026-10-08
- KEV
- no
Provenance
- FIRST EPSS daily exploit-probability · Source record · observed 2026-10-08 17:36:22.845483+00:00 UTC
- NVD CVE API 2.0 · Source record · observed 2026-10-08 17:32:11.049884+00:00 UTC
Stable permalink: https://cybercodered.org/item/cve-cve-2026-9318.html