CVE-2026-34231: 
Python vulnerability analysis and mitigation

Overview

CVE-2026-34231 is a reflected Cross-Site Scripting (XSS) vulnerability in the {% attrs %} template tag of the slippers Django package (pip). When context variables containing untrusted data are passed to {% attrs %}, values are interpolated into HTML attribute strings without escaping, allowing attackers to inject arbitrary HTML or JavaScript. All versions up to and including 0.6.2 are affected; version 0.6.3 contains the fix. The advisory was published on March 30, 2026, with a CVSS v3.1 base score of 6.1 (Medium) (Github Advisory, Slippers Advisory).

Technical details

The root cause is CWE-79 (Improper Neutralization of Input During Web Page Generation). The AttrsNode class is a custom Django template Node subclass registered via register.tag(), which — unlike register.simple_tag() — does not automatically apply conditional_escape() even when Django's autoescape is enabled. The vulnerable attr_string() function uses a raw f-string (f'{key}="{value}"') to construct HTML attribute output, leaving user-supplied values completely unescaped. An attacker can supply a crafted query parameter (e.g., q=" onmouseover="alert(document.cookie)" x=") to any template that passes request data through {% attrs %}, breaking out of the attribute context and injecting event handlers or other HTML (Github Advisory, Slippers Advisory).

Impact

Successful exploitation allows an unauthenticated attacker to inject arbitrary JavaScript into pages rendered for other users, enabling session hijacking via cookie theft, credential phishing, unauthorized actions performed on behalf of victims, and page defacement. The scope is changed (S:C in CVSS terms), meaning the injected script executes in the victim's browser context rather than the server's. Any template passing values from user input, database content, or other untrusted sources to {% attrs %} is vulnerable (Github Advisory).

Exploitability

A proof-of-concept exploit scenario is publicly documented in the GitHub Security Advisory, demonstrating the exact malicious URL parameter needed to trigger XSS. There is no evidence of active in-the-wild exploitation at this time, and the vulnerability is not listed in the CISA KEV catalog. The EPSS score is approximately 0.052% (17th percentile), indicating a low near-term exploitation probability. No threat actor attribution has been reported (Slippers Advisory, Github Advisory).

Exploitation steps

  1. Reconnaissance: Identify web applications built with Django that use the slippers pip package (version ≤ 0.6.2) and expose pages rendered with the {% attrs %} template tag, particularly those passing user-controlled request parameters (e.g., GET/POST query strings) as context variables.
  2. Identify vulnerable template context: Locate endpoints where user-supplied input (e.g., a search query parameter q) is passed directly as a context variable to a template using {% attrs %}, such as render(request, "search.html", {"placeholder": request.GET.get("q", "")}).
  3. Craft malicious payload: Construct a URL with a payload that breaks out of the HTML attribute context, for example: https://example.com/search?q=%22+onmouseover%3D%22alert(document.cookie)%22+x%3D%22 (URL-encoded form of " onmouseover="alert(document.cookie)" x=").
  4. Deliver to victim: Send the crafted URL to a target user via phishing, social engineering, or by embedding it in content that causes the victim's browser to navigate to the URL.
  5. Achieve objective: When the victim loads the page, the injected event handler executes in their browser, enabling the attacker to steal session cookies, perform actions on behalf of the victim, or redirect to a malicious site (Slippers Advisory).

Indicators of compromise

  • Network: HTTP requests to application endpoints containing URL-encoded XSS payloads in query parameters (e.g., %22, onmouseover, onerror, <script> patterns in GET/POST parameters passed to {% attrs %}-using templates.
  • Logs: Web server or Django access logs showing requests with suspicious query strings containing HTML attribute injection patterns such as " on, javascript:, or <script in parameters like q, placeholder, or similar context variable names.
  • Browser/Client-Side: Unexpected JavaScript execution (e.g., alert() dialogs, outbound requests to attacker-controlled domains) triggered by mouse events on form elements rendered by {% attrs %}.
  • Application: Anomalous outbound requests from victim browsers to external domains shortly after loading pages that use the {% attrs %} tag with user-supplied data, potentially indicating cookie exfiltration (Slippers Advisory).

Mitigation and workarounds

Upgrade the slippers package to version 0.6.3, which replaces the vulnerable f-string in attr_string() with Django's format_html() to properly escape both key and value before HTML insertion (Slippers Release, Patch Commit). As a temporary workaround for teams unable to upgrade immediately, sanitize untrusted values in the view layer before passing them to {% attrs %} using django.utils.html.escape(). Additionally, review all templates using {% attrs %} to ensure no user-controlled or database-sourced values are passed without prior validation or escaping (Github Advisory).

Community reactions

The vulnerability was discovered by researcher evansd and responsibly disclosed to the slippers maintainer (mixxorz), who published the advisory and patch on the same day (March 30, 2026). No significant broader media coverage or notable community commentary beyond the GitHub advisory has been identified at this time (Github Advisory).

Additional resources


Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
CVE-2026-105782HIGH7.5
  • Python logoPython
  • scrapy
NoYesOct 06, 2026
GHSA-v853-p72q-4cfwHIGH7.5
  • Python logoPython
  • quart
NoYesOct 05, 2026
CVE-2026-105751MEDIUM6.9
  • Python logoPython
  • docling
NoYesOct 05, 2026
CVE-2026-105750MEDIUM5.9
  • Python logoPython
  • docling
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management