Nixpkgs security tracker

Login with GitHub

Suggestions search

With package: python313Packages.beets-minimal

Found 1 matching suggestions

View:
Compact
Detailed
Published
updated 59 minutes ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    9 packages
    • python312Packages.beets-audible
    • python312Packages.beets-minimal
    • python313Packages.beets-audible
    • python313Packages.beets-minimal
    • python314Packages.beets-audible
    • python312Packages.beets-alternatives
    • python314Packages.beets-alternatives
    • python313Packages.beets-alternatives
    • pkgsRocm.python3Packages.beets-audible
  • @LeSuisse restored
    2 packages
    • python312Packages.beets-minimal
    • python313Packages.beets-minimal
  • @LeSuisse accepted
  • @LeSuisse published on GitHub
beets is Vulnerable to XSS

Beets is the media library management system. Prior to version 2.10.0, the bundled web UI uses Underscore template interpolation mode <%= ... %> for untrusted metadata fields. In this runtime, <%= ... %> is raw insertion and HTML escaping is only performed by <%- ... %>. Rendered output is then inserted with .html(...), allowing attacker-controlled markup to become active DOM. This issue has been patched in version 2.10.0.

Affected products

beets
  • ==< 2.10.0

Matching in nixpkgs

pkgs.beets

Music tagger and library organizer

Ignored packages (7)

Package maintainers