-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability stems from improper Content-Type handling in error responses. The patch adds 'application/json' Content-Type headers in error handlers (commit 7222bd5). Prior to this, error responses (including user-controllable input like URL parameters) were served as text/html, enabling XSS. The affected functions are the error response generators in base handlers, specifically write_error and the json_errors decorator's exception handling logic.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| ipython | pip | >= 3.0.0, < 3.2.0 | 3.2.0 |
Ongoing coverage of React2Shell