{"id":"PYSEC-2023-96","details":"requests-xml v0.2.3 was discovered to contain an XML External Entity Injection (XXE) vulnerability which allows attackers to execute arbitrary code via a crafted XML file.","aliases":["CVE-2020-26708","GHSA-ccrc-9x59-3vc4"],"modified":"2026-06-10T17:02:33.468793558Z","published":"2023-06-29T21:15:00Z","references":[{"type":"REPORT","url":"https://github.com/erinxocon/requests-xml/issues/7"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-ccrc-9x59-3vc4"}],"affected":[{"package":{"name":"requests-xml","ecosystem":"PyPI","purl":"pkg:pypi/requests-xml"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.1.0","0.1.1","0.2.0","0.2.1","0.2.2","0.2.3"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/requests-xml/PYSEC-2023-96.yaml"}}],"schema_version":"1.7.5"}