fonttools is vulnerable to Cross-Site Scripting (XSS)
59
Medium Risk
The fontTools.varLib.interpolatable HTML report embeds glyph names directly into the generated HTML document. Glyph names read from an input font are written into <h1> headings without escaping, so a font whose glyph names contain HTML or script markup injects that markup into the report. Opening the report in a browser then renders the injected markup. The fix escapes glyph names with html.escape before writing them into the report.
You are affected if you are using a version that falls within the vulnerable range and you generate an interpolatable HTML report from untrusted fonts and open that report in a browser.
fonttools is vulnerable to Cross-Site Scripting (XSS) in versions 4.46.0 - 4.64.0.
Upgrade the fonttools library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.