unstructured is vulnerable to Cross-Site Scripting (XSS)
61
Medium Risk
The v2 ontology HTML output path builds HTML from parsed document content without escaping element text or attribute values. Markup contained in an untrusted input document passes through into metadata.text_as_html and elements_to_html() output unchanged. When someone renders that output in a browser, the embedded script executes in their session, producing stored cross-site scripting. The fix centralizes a sanitization policy that escapes text and attribute values, drops event-handler attributes, allowlists tags and attributes, and filters unsafe URL schemes.
You are affected if you are using a version that falls within the vulnerable range and you render HTML produced from untrusted documents via the v2 ontology path.
unstructured is vulnerable to Cross-Site Scripting (XSS) in versions 0.0.1 - 0.24.0.
Upgrade the unstructured library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant