{"id":"CVE-2022-4396","summary":"RDFlib pyrdfa3 __init__.py _get_option cross site scripting","details":"A vulnerability was found in RDFlib pyrdfa3 and classified as problematic. This issue affects the function _get_option of the file pyRdfa/__init__.py. The manipulation leads to cross site scripting. The attack may be initiated remotely. The name of the patch is ffd1d62dd50d5f4190013b39cedcdfbd81f3ce3e. It is recommended to apply a patch to fix this issue. The identifier VDB-215249 was assigned to this vulnerability. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.","aliases":["GHSA-894q-wpg5-mf2h","PYSEC-2026-910"],"modified":"2026-08-12T03:51:27.945401828Z","published":"2022-12-10T00:00:00Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/4xxx/CVE-2022-4396.json","cna_assigner":"VulDB","cwe_ids":["CWE-707"]},"references":[{"type":"WEB","url":"https://vuldb.com/?id.215249"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/4xxx/CVE-2022-4396.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-4396"},{"type":"FIX","url":"https://github.com/RDFLib/pyrdfa3/commit/ffd1d62dd50d5f4190013b39cedcdfbd81f3ce3e"},{"type":"FIX","url":"https://github.com/RDFLib/pyrdfa3/pull/40"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/rdflib/pyrdfa3","events":[{"introduced":"0"},{"fixed":"ffd1d62dd50d5f4190013b39cedcdfbd81f3ce3e"}],"database_specific":{"source":"REFERENCES"}}],"versions":["3.5.2","3.5.1","3.5.0","citable-release"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-4396.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N"}]}