{"id":"PYSEC-2026-1269","summary":"Prevent XSS from Confidant API call","details":"### Impact\n_What kind of vulnerability is it? Who is impacted?_\nPotential XSS from API calls below:\nGET \u003capp\u003e/v1/credentials\nGET \u003capp\u003e/v1/credentials/\u003cid\u003e\nGET \u003capp\u003e/v1/archive/credentials/\u003cid\u003e\nGET \u003capp\u003e/v1/archive/credentials\nPOST \u003capp\u003e/v1/credentials\nPUT \u003capp\u003e/v1/credentials/\u003cid\u003e\nPUT \u003capp\u003e/v1/credentials/\u003cid\u003e/\u003cto_revision\u003e\n\nGET \u003capp\u003e/v1/services\nGET \u003capp\u003e/v1/services/\u003cid\u003e\nGET \u003capp\u003e/v1/archive/services/\u003cid\u003e\nGET \u003capp\u003e/v1/archive/services\nPUT \u003capp\u003e/v1/services/\u003cid\u003e\nPUT \u003capp\u003e/v1/services/\u003cid\u003e/\u003cto_revision\u003e\n\nStored XSS that can only be used as a stored HTML injection. The attacker needs to be authenticated and have privileges to create new credentials, but could use this to show information and run scripts to other users into the same Confidant instance.\n\n### Patches\n_Has the problem been patched? What versions should users upgrade to?_\nyes, version 6.6.2\n\n### Workarounds\n_Is there a way for users to fix or remediate the vulnerability without upgrading?_\nNO\n\n### References\n_Are there any links users can visit to find out more?_\nhttps://hackerone.com/reports/2332004\nhttps://hackerone.com/reports/2456673\nhttps://hackerone.com/reports/2476542\nAcknowledgement: \nThank you Rein Daelman ([trein](https://hackerone.com/trein)) for reporting and proposing the fix.","aliases":["CVE-2024-45793","GHSA-rxq8-q85f-m866"],"modified":"2026-07-07T17:47:12.796163027Z","published":"2026-07-07T14:34:42.224675Z","references":[{"type":"WEB","url":"https://github.com/lyft/confidant/security/advisories/GHSA-rxq8-q85f-m866"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-45793"},{"type":"WEB","url":"https://github.com/lyft/confidant/commit/8876b07abde0c8d2a4974f79b60562b6d0193db9"},{"type":"WEB","url":"https://hackerone.com/reports/2332004"},{"type":"WEB","url":"https://hackerone.com/reports/2456673"},{"type":"WEB","url":"https://hackerone.com/reports/2476542"},{"type":"PACKAGE","url":"https://github.com/lyft/confidant"},{"type":"PACKAGE","url":"https://pypi.org/project/confidant"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-rxq8-q85f-m866"}],"affected":[{"package":{"name":"confidant","ecosystem":"PyPI","purl":"pkg:pypi/confidant"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.6.2"}]}],"versions":["1.1.19","1.1.20","1.1.21","1.10.1","1.11.0","1.2.0","1.3.0","1.4.0","1.5.0","1.5.1","1.6.0","1.8.0","1.9.0","4.0.0","4.1.0","4.2.0","4.3.1","4.4.0","5.0.0","5.0.1","5.1.0","5.2.0","6.0.0","6.1.0","6.2.0","6.3.0","6.4.0","6.5.0","6.5.1","6.5.2","6.5.3","6.6.0","6.6.0a2","6.6.1"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/confidant/PYSEC-2026-1269.yaml"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N"}]}