PyPI: twisted

CVE-2024-41810

Safety vulnerability ID: SFTY-20240729-32631

Safety legacy ID: pyup.io-73795

Affected versions of Twisted are vulnerable to XSS. The `twisted.web.util.redirectTo` function contains an HTML injection vulnerability. If application code allows an attacker to control the redirect URL this vulnerability may result in Reflected Cross-Site Scripting (XSS) in the redirect response HTML body.

Created at: Nov 6, 2025Updated at: Nov 6, 2025

Overview

Twisted vulnerable to HTML injection in HTTP redirect body

Advisory

Affected versions of Twisted are vulnerable to XSS. The `twisted.web.util.redirectTo` function contains an HTML injection vulnerability. If application code allows an attacker to control the redirect URL this vulnerability may result in Reflected Cross-Site Scripting (XSS) in the redirect response HTML body.

Affected Package

Affecting twisted package, versions
<24.7.0rc1

Also affects

---

How to Fix

Upgrade
twisted
to
24.7.0rc1
or higher.

Mitigation and Workarounds

---

Vulnerable Functions

Functions linked to known vulnerabilities.

Vulnerable function data is available for Enterprise customers

Book a call with us to see Safety in action.

Safety

Verified by Safety

Our Cybersecurity Intelligence Team reviewed this vulnerability. We combine public data with our own research to find issues not yet reported to public sources.

Learn more