[CVE-2026-6019] BaseCookie.js_output() does not neutralize characters in cookie value embedded in JS
April 22, 2026
7:29 p.m.
There is a LOW severity vulnerability affecting CPython.
http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes " for JavaScript string context. It does not neutralize the HTML parser-sensitive sequence </script> inside the generated script element. Mitigation base64-encodes the cookie value to disallow escaping using cookie value.
Please see the linked CVE ID for the latest information on affected versions:
115
Age (days ago)
115
Last active (days ago)
0 comments
1 participants
participants (1)
-
Seth Larson