HomeDjangoCVE-2026-34231

CVE-2026-34231

MEDIUM
6.1CVSS
Published: 2026-03-31
Updated: 2026-04-03
AI Analysis

Description

Slippers is a UI component framework for Django. Prior to version 0.6.3, a Cross-Site Scripting (XSS) vulnerability exists in the {% attrs %} template tag of the slippers Django package. When a context variable containing untrusted data is passed to {% attrs %}, the value is interpolated into an HTML attribute string without escaping, allowing an attacker to break out of the attribute context and inject arbitrary HTML or JavaScript into the rendered page. This issue has been patched in version 0.6.3.

CVSS Metrics

Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Attack Vector
network
Complexity
low
Privileges
none
User Action
required
Scope
changed
Confidentiality
low
Integrity
low
Availability
none
Weaknesses
CWE-79

Metadata

Primary Vendor
DJANGO
Published
3/31/2026
Last Modified
4/3/2026
Source
NIST NVD
Note: Verify all details with official vendor sources before applying patches.

Affected Products

django : slippers

AI-Powered Remediation

Generate remediation guidance or a C-suite brief for this vulnerability.

Executive Intelligence Brief

CVE-CVE-2026-34231 | MEDIUM Severity | CVEDatabase.com | CVEDatabase.com