{"id":"PYSEC-2023-95","details":"py-xml v1.0 was discovered to contain an XML External Entity Injection (XXE) vulnerability which allows attackers to execute arbitrary code via a crafted XML file.","aliases":["CVE-2020-26709","GHSA-j6v2-mwxm-f952"],"modified":"2026-06-10T17:01:39.343136903Z","published":"2023-06-29T21:15:00Z","references":[{"type":"REPORT","url":"https://github.com/PinaeOS/py-xml/issues/2"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-j6v2-mwxm-f952"}],"affected":[{"package":{"name":"py-xml","ecosystem":"PyPI","purl":"pkg:pypi/py-xml"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.0"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/py-xml/PYSEC-2023-95.yaml"}}],"schema_version":"1.7.5"}