
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-33140 is a stored Cross-Site Scripting (XSS) vulnerability in PySpector, a Python static analysis tool, affecting all versions up to and including 0.1.6. When PySpector scans a Python file containing JavaScript payloads embedded in strings passed to eval(), the flagged code snippet is interpolated into the generated HTML report without sanitization. Opening the report in a browser causes the embedded JavaScript to execute in the local file context. The vulnerability was published by the maintainer on March 17, 2026, and assigned a CVSS v3.1 score of 6.1 (Medium) and a CVSS v4.0 score of 5.3 (Medium) (GitHub Advisory, PySpector Advisory).
The root cause is CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-Site Scripting): PySpector interpolates flagged code snippets directly into HTML report output without escaping or sanitizing user-controlled content. Specifically, when a Python file contains a JavaScript payload inside a string argument to eval(), PySpector's report generator embeds the raw snippet into the HTML, which the browser then executes as script when the report is opened. Exploitation requires no privileges or authentication — the attacker only needs to craft a malicious Python file (e.g., hosted in a public repository) and induce a victim to scan it with PySpector and open the resulting HTML report. A proof-of-concept with step-by-step reproduction instructions is publicly available (PySpector Advisory).
Successful exploitation allows arbitrary JavaScript execution in the victim's browser under the file:// context. While this limits cookie theft and credentialed cross-origin requests, an attacker can still perform arbitrary DOM manipulation, redirect the victim to attacker-controlled pages, and potentially exfiltrate locally accessible data via fetch() or XMLHttpRequest to file:// paths (browser-dependent). Any PySpector user who scans untrusted Python code and opens the generated HTML report is at risk (GitHub Advisory, PySpector Advisory).
A public proof-of-concept with detailed reproduction steps is available in the official security advisory, confirmed as a real exploit with high confidence by Feedly threat intelligence (PySpector Advisory). There is no evidence of active in-the-wild exploitation or threat actor attribution at this time. The EPSS score is approximately 0.047% (4th percentile), indicating a low current probability of exploitation in the wild. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.
eval(), for example:eval("<script>alert('XSS')</script>")This can be hosted in a public repository to increase reach.
Induce victim to scan the file: Social-engineer or otherwise cause a PySpector user (running version ≤ 0.1.6) to scan the malicious Python file using PySpector, which generates an HTML report.
HTML report generation: PySpector flags the eval() call as suspicious and interpolates the raw code snippet — including the embedded JavaScript payload — directly into the HTML report without sanitization.
Trigger execution: When the victim opens the generated HTML report in any browser, the embedded JavaScript executes in the file:// context, enabling DOM manipulation, redirects to attacker-controlled pages, or attempts to read locally accessible files via fetch() or XMLHttpRequest (PySpector Advisory).
report.html) containing unsanitized <script> tags or JavaScript event handlers within code snippet sections of the report.eval() string arguments (e.g., eval("<script>...</script>")).file:// paths originating from a locally opened HTML report.Upgrade PySpector to version 0.1.7 or later, which patches the stored XSS vulnerability by properly sanitizing code snippets before interpolating them into HTML reports (GitHub Advisory). As an interim workaround, avoid scanning untrusted or unknown Python files with PySpector, and refrain from opening HTML reports generated from untrusted sources. Users may also consider disabling JavaScript execution in their browser when viewing local HTML files, or opening reports in a sandboxed environment.
The vulnerability was credited to researcher satoridev01 and disclosed responsibly through GitHub's security advisory process (PySpector Advisory). Brief mentions appeared on CVE tracking feeds and social media (Twitter/X via CVEnew) shortly after publication, and it was included in a Loginsoft weekly threat landscape summary on Medium. No significant broader media coverage or notable researcher commentary beyond the advisory itself has been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."