-
Notifications
You must be signed in to change notification settings - Fork 314
Open
Description
While working in SimpleMen project, I found that the application uses nltk, which is affected by a reflected XSS vulnerability (CVE-2026-33230). The issue exists in the WordNet web app (lookup_ route), where user-controlled input is reflected into HTML without proper sanitization. This allows attackers to inject malicious scripts, potentially leading to unauthorized actions or data exposure in the user’s browser.
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
No labels