logo

Database

XML injection (XXE) In biopython

Description

Biopython is vulnerable to doctype XML external entity (XXE) injection through Bio.Entrez Bio.Entrez in Biopython through 1.86 allows doctype XXE.

Mitigation

Update Impact

Minimal update. May introduce new vulnerabilities or breaking changes.

Ecosystem
Component
Affected version
Patched versions