PT-2025-45658 · Pypi · Ckan

Published

2025-10-29

·

Updated

2025-10-29

CVSS v3.1

6.3

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:N

Impact

The helpers.markdown extract() function did not perform sufficient sanitization of input data before wrapping in an HTML literal element. This helper is used to render user-provided data on dataset, resource, organization or group pages (plus any page provided by an extension that used that helper function), leading to a potential XSS vector.

Patches

This vulnerability has been fixed in CKAN 2.10.9 and 2.11.4

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

GHSA-2R4H-8JXV-W2J8

Affected Products

Ckan