CVE-2022-25303
Python vulnerability analysis and mitigation

Overview

CVE-2022-25303 is a Cross-site Scripting (XSS) vulnerability affecting whoogle-search package versions prior to 0.7.2. The vulnerability was discovered by Alessio Della Libera of Snyk Security Team and was disclosed on April 26, 2022 (Snyk).

Technical details

The vulnerability exists in the query string parameter 'q'. When this parameter does not contain the 'http' string, it is used to build the error_message that is rendered in the error.html template using the flask.render_template function. The critical issue is that the error_message is rendered using the '|safe' filter, which means the user input is not escaped, allowing for potential XSS attacks (Snyk).

Impact

This vulnerability allows attackers to execute malicious scripts in the context of the user's browser session. The successful exploitation could lead to cookie theft, session hijacking, exposure of sensitive information, access to privileged services and functionality, or delivery of malware (Snyk).

Mitigation and workarounds

The vulnerability was fixed in whoogle-search version 0.7.2. The fix involved removing the '|safe' filter from the error.html template, ensuring proper escaping of user input. Organizations should upgrade to version 0.7.2 or higher to address this vulnerability (GitHub).

Additional resources


SourceThis report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-5882-5rx9-xgxpCRITICAL10
  • PythonPython
  • crawl4ai
NoYesJan 16, 2026
GHSA-vx9w-5cx4-9796HIGH8.6
  • PythonPython
  • crawl4ai
NoYesJan 16, 2026
CVE-2026-23535HIGH8
  • PythonPython
  • wlc
NoYesJan 16, 2026
CVE-2026-23490HIGH7.5
  • PythonPython
  • pyasn1
NoYesJan 16, 2026
CVE-2026-23528MEDIUM5.3
  • PythonPython
  • distributed
NoYesJan 16, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management