PyPI: feedparser

CVE-2011-1157

Safety vulnerability ID: SFTY-20110411-25083

Safety legacy ID: pyup.io-33126

Cross-site scripting (XSS) vulnerability in feedparser.py in Universal Feed Parser (aka feedparser or python-feedparser) 5.x before 5.0.1 allows remote attackers to inject arbitrary web script or HTML via malformed XML comments.

Created at: Apr 29, 2026Updated at: Apr 29, 2026

Overview

feedparser Cross-site Scripting vulnerability

Advisory

Cross-site scripting (XSS) vulnerability in feedparser.py in Universal Feed Parser (aka feedparser or python-feedparser) 5.x before 5.0.1 allows remote attackers to inject arbitrary web script or HTML via malformed XML comments.

Affected Package

Affecting feedparser package, versions
<5.0.1

Also affects

---

How to Fix

Upgrade
feedparser
to
5.0.1
or higher.

Mitigation and Workarounds

---

Vulnerable Functions

Functions linked to known vulnerabilities.

Vulnerable function data is available for Enterprise customers

Book a call with us to see Safety in action.

Safety

Verified by Safety

Our Cybersecurity Intelligence Team reviewed this vulnerability. We combine public data with our own research to find issues not yet reported to public sources.

Learn more