django-tomselect
Django autocomplete widgets and views using Tom Select
Activity
- Latest release
- 3mo ago
- Total releases
- 57
- Cadence
- ~3 days
- Last 12 months
- 15
Reach
- Stars
- —
Details
- License
- MIT
- First release
- Jul 02, 2023
| Version | Released | |
|---|---|---|
2026.6.2
patch
| ||
2026.6.1
minor
| ||
2026.5.6
patch
| ||
2026.5.5
patch
| ||
2026.5.4
patch
| ||
2026.5.3
patch
| ||
2026.5.2
patch
| ||
2026.5.1
minor
| ||
2026.4.1
minor
| ||
2026.3.3
patch
| ||
2026.3.2
patch
| ||
2026.3.1
minor
| ||
2026.1.3
patch
| ||
2026.1.2
patch
| ||
2026.1.1
major
| ||
2025.9.1
minor
| ||
2025.7.1
minor
| ||
2025.5.7
patch
| ||
2025.5.6
patch
| ||
2025.5.5
patch
| ||
2025.5.4
patch
| ||
2025.5.3
patch
| ||
2025.5.2
patch
| ||
2025.5.1
minor
| ||
2025.3.4
patch
| ||
2025.3.3
patch
| ||
2025.3.2
patch
1 CVE
GHSA-785h-76cm-cpmf
Mar 26, 2025
Django TomSelect incomplete escaping of dangerous characters in widget attributes
Low
Network
High
None
None
SummaryUser supplied values passed through to certain attributes in form widgets are not fully escaped for potentially dangerous tokens, and in some cases are rendered in browser as valid html tags. DetailsAttributes passed to the widget (such as For example, a label of: The actual output rendered in the browser for this example is: The script tags appears to be valid in Chrome dev tools, but doesn't appear execute code. ImpactAlthough the risk may be mediated since the content within the rendered Because of the relatively small number of users at this moment, our plan to yank affected releases on PyPI and GitHub, and because raw text is rendered but does not seem to be executable, I am marking the Severity Low. Update to version 5.3.3. The only difference from 5.3.2 is the code and documentation changes to resolve this vulnerability, so the update process should not be problematic. Affected versions
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.1b0
0.5.1b1
0.5.1b10
0.5.1b11
0.5.1b2
0.5.1b3
0.5.1b4
+ 19 more Show less
0.5.1b5
0.5.1b6
0.5.1b7
0.5.1b8
0.5.1b9
2024.12.1
2024.12.2
2024.12.3
2024.12.4
2024.12.5
2024.12.6
2024.12.7
2025.1.1
2025.1.2
2025.2.1
2025.2.2
2025.2.3
2025.3.1
2025.3.2
Fixed in
2025.3.3
References Updated Apr 06, 2025 · Source: OSV.dev | ||
2025.3.1
minor
1 CVE
GHSA-785h-76cm-cpmf
Mar 26, 2025
Django TomSelect incomplete escaping of dangerous characters in widget attributes
Low
Network
High
None
None
SummaryUser supplied values passed through to certain attributes in form widgets are not fully escaped for potentially dangerous tokens, and in some cases are rendered in browser as valid html tags. DetailsAttributes passed to the widget (such as For example, a label of: The actual output rendered in the browser for this example is: The script tags appears to be valid in Chrome dev tools, but doesn't appear execute code. ImpactAlthough the risk may be mediated since the content within the rendered Because of the relatively small number of users at this moment, our plan to yank affected releases on PyPI and GitHub, and because raw text is rendered but does not seem to be executable, I am marking the Severity Low. Update to version 5.3.3. The only difference from 5.3.2 is the code and documentation changes to resolve this vulnerability, so the update process should not be problematic. Affected versions
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.1b0
0.5.1b1
0.5.1b10
0.5.1b11
0.5.1b2
0.5.1b3
0.5.1b4
+ 19 more Show less
0.5.1b5
0.5.1b6
0.5.1b7
0.5.1b8
0.5.1b9
2024.12.1
2024.12.2
2024.12.3
2024.12.4
2024.12.5
2024.12.6
2024.12.7
2025.1.1
2025.1.2
2025.2.1
2025.2.2
2025.2.3
2025.3.1
2025.3.2
Fixed in
2025.3.3
References Updated Apr 06, 2025 · Source: OSV.dev | ||
2025.2.3
patch
1 CVE
GHSA-785h-76cm-cpmf
Mar 26, 2025
Django TomSelect incomplete escaping of dangerous characters in widget attributes
Low
Network
High
None
None
SummaryUser supplied values passed through to certain attributes in form widgets are not fully escaped for potentially dangerous tokens, and in some cases are rendered in browser as valid html tags. DetailsAttributes passed to the widget (such as For example, a label of: The actual output rendered in the browser for this example is: The script tags appears to be valid in Chrome dev tools, but doesn't appear execute code. ImpactAlthough the risk may be mediated since the content within the rendered Because of the relatively small number of users at this moment, our plan to yank affected releases on PyPI and GitHub, and because raw text is rendered but does not seem to be executable, I am marking the Severity Low. Update to version 5.3.3. The only difference from 5.3.2 is the code and documentation changes to resolve this vulnerability, so the update process should not be problematic. Affected versions
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.1b0
0.5.1b1
0.5.1b10
0.5.1b11
0.5.1b2
0.5.1b3
0.5.1b4
+ 19 more Show less
0.5.1b5
0.5.1b6
0.5.1b7
0.5.1b8
0.5.1b9
2024.12.1
2024.12.2
2024.12.3
2024.12.4
2024.12.5
2024.12.6
2024.12.7
2025.1.1
2025.1.2
2025.2.1
2025.2.2
2025.2.3
2025.3.1
2025.3.2
Fixed in
2025.3.3
References Updated Apr 06, 2025 · Source: OSV.dev | ||
2025.2.2
patch
1 CVE
GHSA-785h-76cm-cpmf
Mar 26, 2025
Django TomSelect incomplete escaping of dangerous characters in widget attributes
Low
Network
High
None
None
SummaryUser supplied values passed through to certain attributes in form widgets are not fully escaped for potentially dangerous tokens, and in some cases are rendered in browser as valid html tags. DetailsAttributes passed to the widget (such as For example, a label of: The actual output rendered in the browser for this example is: The script tags appears to be valid in Chrome dev tools, but doesn't appear execute code. ImpactAlthough the risk may be mediated since the content within the rendered Because of the relatively small number of users at this moment, our plan to yank affected releases on PyPI and GitHub, and because raw text is rendered but does not seem to be executable, I am marking the Severity Low. Update to version 5.3.3. The only difference from 5.3.2 is the code and documentation changes to resolve this vulnerability, so the update process should not be problematic. Affected versions
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.1b0
0.5.1b1
0.5.1b10
0.5.1b11
0.5.1b2
0.5.1b3
0.5.1b4
+ 19 more Show less
0.5.1b5
0.5.1b6
0.5.1b7
0.5.1b8
0.5.1b9
2024.12.1
2024.12.2
2024.12.3
2024.12.4
2024.12.5
2024.12.6
2024.12.7
2025.1.1
2025.1.2
2025.2.1
2025.2.2
2025.2.3
2025.3.1
2025.3.2
Fixed in
2025.3.3
References Updated Apr 06, 2025 · Source: OSV.dev | ||
2025.2.1
minor
1 CVE
GHSA-785h-76cm-cpmf
Mar 26, 2025
Django TomSelect incomplete escaping of dangerous characters in widget attributes
Low
Network
High
None
None
SummaryUser supplied values passed through to certain attributes in form widgets are not fully escaped for potentially dangerous tokens, and in some cases are rendered in browser as valid html tags. DetailsAttributes passed to the widget (such as For example, a label of: The actual output rendered in the browser for this example is: The script tags appears to be valid in Chrome dev tools, but doesn't appear execute code. ImpactAlthough the risk may be mediated since the content within the rendered Because of the relatively small number of users at this moment, our plan to yank affected releases on PyPI and GitHub, and because raw text is rendered but does not seem to be executable, I am marking the Severity Low. Update to version 5.3.3. The only difference from 5.3.2 is the code and documentation changes to resolve this vulnerability, so the update process should not be problematic. Affected versions
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.1b0
0.5.1b1
0.5.1b10
0.5.1b11
0.5.1b2
0.5.1b3
0.5.1b4
+ 19 more Show less
0.5.1b5
0.5.1b6
0.5.1b7
0.5.1b8
0.5.1b9
2024.12.1
2024.12.2
2024.12.3
2024.12.4
2024.12.5
2024.12.6
2024.12.7
2025.1.1
2025.1.2
2025.2.1
2025.2.2
2025.2.3
2025.3.1
2025.3.2
Fixed in
2025.3.3
References Updated Apr 06, 2025 · Source: OSV.dev | ||
2025.1.2
patch
1 CVE
GHSA-785h-76cm-cpmf
Mar 26, 2025
Django TomSelect incomplete escaping of dangerous characters in widget attributes
Low
Network
High
None
None
SummaryUser supplied values passed through to certain attributes in form widgets are not fully escaped for potentially dangerous tokens, and in some cases are rendered in browser as valid html tags. DetailsAttributes passed to the widget (such as For example, a label of: The actual output rendered in the browser for this example is: The script tags appears to be valid in Chrome dev tools, but doesn't appear execute code. ImpactAlthough the risk may be mediated since the content within the rendered Because of the relatively small number of users at this moment, our plan to yank affected releases on PyPI and GitHub, and because raw text is rendered but does not seem to be executable, I am marking the Severity Low. Update to version 5.3.3. The only difference from 5.3.2 is the code and documentation changes to resolve this vulnerability, so the update process should not be problematic. Affected versions
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.1b0
0.5.1b1
0.5.1b10
0.5.1b11
0.5.1b2
0.5.1b3
0.5.1b4
+ 19 more Show less
0.5.1b5
0.5.1b6
0.5.1b7
0.5.1b8
0.5.1b9
2024.12.1
2024.12.2
2024.12.3
2024.12.4
2024.12.5
2024.12.6
2024.12.7
2025.1.1
2025.1.2
2025.2.1
2025.2.2
2025.2.3
2025.3.1
2025.3.2
Fixed in
2025.3.3
References Updated Apr 06, 2025 · Source: OSV.dev | ||
2025.1.1
major
1 CVE
GHSA-785h-76cm-cpmf
Mar 26, 2025
Django TomSelect incomplete escaping of dangerous characters in widget attributes
Low
Network
High
None
None
SummaryUser supplied values passed through to certain attributes in form widgets are not fully escaped for potentially dangerous tokens, and in some cases are rendered in browser as valid html tags. DetailsAttributes passed to the widget (such as For example, a label of: The actual output rendered in the browser for this example is: The script tags appears to be valid in Chrome dev tools, but doesn't appear execute code. ImpactAlthough the risk may be mediated since the content within the rendered Because of the relatively small number of users at this moment, our plan to yank affected releases on PyPI and GitHub, and because raw text is rendered but does not seem to be executable, I am marking the Severity Low. Update to version 5.3.3. The only difference from 5.3.2 is the code and documentation changes to resolve this vulnerability, so the update process should not be problematic. Affected versions
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.1b0
0.5.1b1
0.5.1b10
0.5.1b11
0.5.1b2
0.5.1b3
0.5.1b4
+ 19 more Show less
0.5.1b5
0.5.1b6
0.5.1b7
0.5.1b8
0.5.1b9
2024.12.1
2024.12.2
2024.12.3
2024.12.4
2024.12.5
2024.12.6
2024.12.7
2025.1.1
2025.1.2
2025.2.1
2025.2.2
2025.2.3
2025.3.1
2025.3.2
Fixed in
2025.3.3
References Updated Apr 06, 2025 · Source: OSV.dev | ||
2024.12.7
patch
1 CVE
GHSA-785h-76cm-cpmf
Mar 26, 2025
Django TomSelect incomplete escaping of dangerous characters in widget attributes
Low
Network
High
None
None
SummaryUser supplied values passed through to certain attributes in form widgets are not fully escaped for potentially dangerous tokens, and in some cases are rendered in browser as valid html tags. DetailsAttributes passed to the widget (such as For example, a label of: The actual output rendered in the browser for this example is: The script tags appears to be valid in Chrome dev tools, but doesn't appear execute code. ImpactAlthough the risk may be mediated since the content within the rendered Because of the relatively small number of users at this moment, our plan to yank affected releases on PyPI and GitHub, and because raw text is rendered but does not seem to be executable, I am marking the Severity Low. Update to version 5.3.3. The only difference from 5.3.2 is the code and documentation changes to resolve this vulnerability, so the update process should not be problematic. Affected versions
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.1b0
0.5.1b1
0.5.1b10
0.5.1b11
0.5.1b2
0.5.1b3
0.5.1b4
+ 19 more Show less
0.5.1b5
0.5.1b6
0.5.1b7
0.5.1b8
0.5.1b9
2024.12.1
2024.12.2
2024.12.3
2024.12.4
2024.12.5
2024.12.6
2024.12.7
2025.1.1
2025.1.2
2025.2.1
2025.2.2
2025.2.3
2025.3.1
2025.3.2
Fixed in
2025.3.3
References Updated Apr 06, 2025 · Source: OSV.dev | ||
2024.12.6
patch
1 CVE
GHSA-785h-76cm-cpmf
Mar 26, 2025
Django TomSelect incomplete escaping of dangerous characters in widget attributes
Low
Network
High
None
None
SummaryUser supplied values passed through to certain attributes in form widgets are not fully escaped for potentially dangerous tokens, and in some cases are rendered in browser as valid html tags. DetailsAttributes passed to the widget (such as For example, a label of: The actual output rendered in the browser for this example is: The script tags appears to be valid in Chrome dev tools, but doesn't appear execute code. ImpactAlthough the risk may be mediated since the content within the rendered Because of the relatively small number of users at this moment, our plan to yank affected releases on PyPI and GitHub, and because raw text is rendered but does not seem to be executable, I am marking the Severity Low. Update to version 5.3.3. The only difference from 5.3.2 is the code and documentation changes to resolve this vulnerability, so the update process should not be problematic. Affected versions
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.1b0
0.5.1b1
0.5.1b10
0.5.1b11
0.5.1b2
0.5.1b3
0.5.1b4
+ 19 more Show less
0.5.1b5
0.5.1b6
0.5.1b7
0.5.1b8
0.5.1b9
2024.12.1
2024.12.2
2024.12.3
2024.12.4
2024.12.5
2024.12.6
2024.12.7
2025.1.1
2025.1.2
2025.2.1
2025.2.2
2025.2.3
2025.3.1
2025.3.2
Fixed in
2025.3.3
References Updated Apr 06, 2025 · Source: OSV.dev | ||
2024.12.5
patch
1 CVE
GHSA-785h-76cm-cpmf
Mar 26, 2025
Django TomSelect incomplete escaping of dangerous characters in widget attributes
Low
Network
High
None
None
SummaryUser supplied values passed through to certain attributes in form widgets are not fully escaped for potentially dangerous tokens, and in some cases are rendered in browser as valid html tags. DetailsAttributes passed to the widget (such as For example, a label of: The actual output rendered in the browser for this example is: The script tags appears to be valid in Chrome dev tools, but doesn't appear execute code. ImpactAlthough the risk may be mediated since the content within the rendered Because of the relatively small number of users at this moment, our plan to yank affected releases on PyPI and GitHub, and because raw text is rendered but does not seem to be executable, I am marking the Severity Low. Update to version 5.3.3. The only difference from 5.3.2 is the code and documentation changes to resolve this vulnerability, so the update process should not be problematic. Affected versions
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.1b0
0.5.1b1
0.5.1b10
0.5.1b11
0.5.1b2
0.5.1b3
0.5.1b4
+ 19 more Show less
0.5.1b5
0.5.1b6
0.5.1b7
0.5.1b8
0.5.1b9
2024.12.1
2024.12.2
2024.12.3
2024.12.4
2024.12.5
2024.12.6
2024.12.7
2025.1.1
2025.1.2
2025.2.1
2025.2.2
2025.2.3
2025.3.1
2025.3.2
Fixed in
2025.3.3
References Updated Apr 06, 2025 · Source: OSV.dev | ||
2024.12.4
patch
1 CVE
GHSA-785h-76cm-cpmf
Mar 26, 2025
Django TomSelect incomplete escaping of dangerous characters in widget attributes
Low
Network
High
None
None
SummaryUser supplied values passed through to certain attributes in form widgets are not fully escaped for potentially dangerous tokens, and in some cases are rendered in browser as valid html tags. DetailsAttributes passed to the widget (such as For example, a label of: The actual output rendered in the browser for this example is: The script tags appears to be valid in Chrome dev tools, but doesn't appear execute code. ImpactAlthough the risk may be mediated since the content within the rendered Because of the relatively small number of users at this moment, our plan to yank affected releases on PyPI and GitHub, and because raw text is rendered but does not seem to be executable, I am marking the Severity Low. Update to version 5.3.3. The only difference from 5.3.2 is the code and documentation changes to resolve this vulnerability, so the update process should not be problematic. Affected versions
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.1b0
0.5.1b1
0.5.1b10
0.5.1b11
0.5.1b2
0.5.1b3
0.5.1b4
+ 19 more Show less
0.5.1b5
0.5.1b6
0.5.1b7
0.5.1b8
0.5.1b9
2024.12.1
2024.12.2
2024.12.3
2024.12.4
2024.12.5
2024.12.6
2024.12.7
2025.1.1
2025.1.2
2025.2.1
2025.2.2
2025.2.3
2025.3.1
2025.3.2
Fixed in
2025.3.3
References Updated Apr 06, 2025 · Source: OSV.dev | ||
2024.12.3
patch
1 CVE
GHSA-785h-76cm-cpmf
Mar 26, 2025
Django TomSelect incomplete escaping of dangerous characters in widget attributes
Low
Network
High
None
None
SummaryUser supplied values passed through to certain attributes in form widgets are not fully escaped for potentially dangerous tokens, and in some cases are rendered in browser as valid html tags. DetailsAttributes passed to the widget (such as For example, a label of: The actual output rendered in the browser for this example is: The script tags appears to be valid in Chrome dev tools, but doesn't appear execute code. ImpactAlthough the risk may be mediated since the content within the rendered Because of the relatively small number of users at this moment, our plan to yank affected releases on PyPI and GitHub, and because raw text is rendered but does not seem to be executable, I am marking the Severity Low. Update to version 5.3.3. The only difference from 5.3.2 is the code and documentation changes to resolve this vulnerability, so the update process should not be problematic. Affected versions
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.1b0
0.5.1b1
0.5.1b10
0.5.1b11
0.5.1b2
0.5.1b3
0.5.1b4
+ 19 more Show less
0.5.1b5
0.5.1b6
0.5.1b7
0.5.1b8
0.5.1b9
2024.12.1
2024.12.2
2024.12.3
2024.12.4
2024.12.5
2024.12.6
2024.12.7
2025.1.1
2025.1.2
2025.2.1
2025.2.2
2025.2.3
2025.3.1
2025.3.2
Fixed in
2025.3.3
References Updated Apr 06, 2025 · Source: OSV.dev | ||
2024.12.2
patch
1 CVE
GHSA-785h-76cm-cpmf
Mar 26, 2025
Django TomSelect incomplete escaping of dangerous characters in widget attributes
Low
Network
High
None
None
SummaryUser supplied values passed through to certain attributes in form widgets are not fully escaped for potentially dangerous tokens, and in some cases are rendered in browser as valid html tags. DetailsAttributes passed to the widget (such as For example, a label of: The actual output rendered in the browser for this example is: The script tags appears to be valid in Chrome dev tools, but doesn't appear execute code. ImpactAlthough the risk may be mediated since the content within the rendered Because of the relatively small number of users at this moment, our plan to yank affected releases on PyPI and GitHub, and because raw text is rendered but does not seem to be executable, I am marking the Severity Low. Update to version 5.3.3. The only difference from 5.3.2 is the code and documentation changes to resolve this vulnerability, so the update process should not be problematic. Affected versions
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.1b0
0.5.1b1
0.5.1b10
0.5.1b11
0.5.1b2
0.5.1b3
0.5.1b4
+ 19 more Show less
0.5.1b5
0.5.1b6
0.5.1b7
0.5.1b8
0.5.1b9
2024.12.1
2024.12.2
2024.12.3
2024.12.4
2024.12.5
2024.12.6
2024.12.7
2025.1.1
2025.1.2
2025.2.1
2025.2.2
2025.2.3
2025.3.1
2025.3.2
Fixed in
2025.3.3
References Updated Apr 06, 2025 · Source: OSV.dev | ||
2024.12.1
major
1 CVE
GHSA-785h-76cm-cpmf
Mar 26, 2025
Django TomSelect incomplete escaping of dangerous characters in widget attributes
Low
Network
High
None
None
SummaryUser supplied values passed through to certain attributes in form widgets are not fully escaped for potentially dangerous tokens, and in some cases are rendered in browser as valid html tags. DetailsAttributes passed to the widget (such as For example, a label of: The actual output rendered in the browser for this example is: The script tags appears to be valid in Chrome dev tools, but doesn't appear execute code. ImpactAlthough the risk may be mediated since the content within the rendered Because of the relatively small number of users at this moment, our plan to yank affected releases on PyPI and GitHub, and because raw text is rendered but does not seem to be executable, I am marking the Severity Low. Update to version 5.3.3. The only difference from 5.3.2 is the code and documentation changes to resolve this vulnerability, so the update process should not be problematic. Affected versions
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.1b0
0.5.1b1
0.5.1b10
0.5.1b11
0.5.1b2
0.5.1b3
0.5.1b4
+ 19 more Show less
0.5.1b5
0.5.1b6
0.5.1b7
0.5.1b8
0.5.1b9
2024.12.1
2024.12.2
2024.12.3
2024.12.4
2024.12.5
2024.12.6
2024.12.7
2025.1.1
2025.1.2
2025.2.1
2025.2.2
2025.2.3
2025.3.1
2025.3.2
Fixed in
2025.3.3
References Updated Apr 06, 2025 · Source: OSV.dev | ||
0.5.1b11
pre
1 CVE
GHSA-785h-76cm-cpmf
Mar 26, 2025
Django TomSelect incomplete escaping of dangerous characters in widget attributes
Low
Network
High
None
None
SummaryUser supplied values passed through to certain attributes in form widgets are not fully escaped for potentially dangerous tokens, and in some cases are rendered in browser as valid html tags. DetailsAttributes passed to the widget (such as For example, a label of: The actual output rendered in the browser for this example is: The script tags appears to be valid in Chrome dev tools, but doesn't appear execute code. ImpactAlthough the risk may be mediated since the content within the rendered Because of the relatively small number of users at this moment, our plan to yank affected releases on PyPI and GitHub, and because raw text is rendered but does not seem to be executable, I am marking the Severity Low. Update to version 5.3.3. The only difference from 5.3.2 is the code and documentation changes to resolve this vulnerability, so the update process should not be problematic. Affected versions
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.1b0
0.5.1b1
0.5.1b10
0.5.1b11
0.5.1b2
0.5.1b3
0.5.1b4
+ 19 more Show less
0.5.1b5
0.5.1b6
0.5.1b7
0.5.1b8
0.5.1b9
2024.12.1
2024.12.2
2024.12.3
2024.12.4
2024.12.5
2024.12.6
2024.12.7
2025.1.1
2025.1.2
2025.2.1
2025.2.2
2025.2.3
2025.3.1
2025.3.2
Fixed in
2025.3.3
References Updated Apr 06, 2025 · Source: OSV.dev | ||
0.5.1b10
pre
1 CVE
GHSA-785h-76cm-cpmf
Mar 26, 2025
Django TomSelect incomplete escaping of dangerous characters in widget attributes
Low
Network
High
None
None
SummaryUser supplied values passed through to certain attributes in form widgets are not fully escaped for potentially dangerous tokens, and in some cases are rendered in browser as valid html tags. DetailsAttributes passed to the widget (such as For example, a label of: The actual output rendered in the browser for this example is: The script tags appears to be valid in Chrome dev tools, but doesn't appear execute code. ImpactAlthough the risk may be mediated since the content within the rendered Because of the relatively small number of users at this moment, our plan to yank affected releases on PyPI and GitHub, and because raw text is rendered but does not seem to be executable, I am marking the Severity Low. Update to version 5.3.3. The only difference from 5.3.2 is the code and documentation changes to resolve this vulnerability, so the update process should not be problematic. Affected versions
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.1b0
0.5.1b1
0.5.1b10
0.5.1b11
0.5.1b2
0.5.1b3
0.5.1b4
+ 19 more Show less
0.5.1b5
0.5.1b6
0.5.1b7
0.5.1b8
0.5.1b9
2024.12.1
2024.12.2
2024.12.3
2024.12.4
2024.12.5
2024.12.6
2024.12.7
2025.1.1
2025.1.2
2025.2.1
2025.2.2
2025.2.3
2025.3.1
2025.3.2
Fixed in
2025.3.3
References Updated Apr 06, 2025 · Source: OSV.dev | ||
0.5.1b9
pre
1 CVE
GHSA-785h-76cm-cpmf
Mar 26, 2025
Django TomSelect incomplete escaping of dangerous characters in widget attributes
Low
Network
High
None
None
SummaryUser supplied values passed through to certain attributes in form widgets are not fully escaped for potentially dangerous tokens, and in some cases are rendered in browser as valid html tags. DetailsAttributes passed to the widget (such as For example, a label of: The actual output rendered in the browser for this example is: The script tags appears to be valid in Chrome dev tools, but doesn't appear execute code. ImpactAlthough the risk may be mediated since the content within the rendered Because of the relatively small number of users at this moment, our plan to yank affected releases on PyPI and GitHub, and because raw text is rendered but does not seem to be executable, I am marking the Severity Low. Update to version 5.3.3. The only difference from 5.3.2 is the code and documentation changes to resolve this vulnerability, so the update process should not be problematic. Affected versions
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.1b0
0.5.1b1
0.5.1b10
0.5.1b11
0.5.1b2
0.5.1b3
0.5.1b4
+ 19 more Show less
0.5.1b5
0.5.1b6
0.5.1b7
0.5.1b8
0.5.1b9
2024.12.1
2024.12.2
2024.12.3
2024.12.4
2024.12.5
2024.12.6
2024.12.7
2025.1.1
2025.1.2
2025.2.1
2025.2.2
2025.2.3
2025.3.1
2025.3.2
Fixed in
2025.3.3
References Updated Apr 06, 2025 · Source: OSV.dev | ||
0.5.1b8
pre
1 CVE
GHSA-785h-76cm-cpmf
Mar 26, 2025
Django TomSelect incomplete escaping of dangerous characters in widget attributes
Low
Network
High
None
None
SummaryUser supplied values passed through to certain attributes in form widgets are not fully escaped for potentially dangerous tokens, and in some cases are rendered in browser as valid html tags. DetailsAttributes passed to the widget (such as For example, a label of: The actual output rendered in the browser for this example is: The script tags appears to be valid in Chrome dev tools, but doesn't appear execute code. ImpactAlthough the risk may be mediated since the content within the rendered Because of the relatively small number of users at this moment, our plan to yank affected releases on PyPI and GitHub, and because raw text is rendered but does not seem to be executable, I am marking the Severity Low. Update to version 5.3.3. The only difference from 5.3.2 is the code and documentation changes to resolve this vulnerability, so the update process should not be problematic. Affected versions
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.1b0
0.5.1b1
0.5.1b10
0.5.1b11
0.5.1b2
0.5.1b3
0.5.1b4
+ 19 more Show less
0.5.1b5
0.5.1b6
0.5.1b7
0.5.1b8
0.5.1b9
2024.12.1
2024.12.2
2024.12.3
2024.12.4
2024.12.5
2024.12.6
2024.12.7
2025.1.1
2025.1.2
2025.2.1
2025.2.2
2025.2.3
2025.3.1
2025.3.2
Fixed in
2025.3.3
References Updated Apr 06, 2025 · Source: OSV.dev | ||
0.5.1b7
pre
1 CVE
GHSA-785h-76cm-cpmf
Mar 26, 2025
Django TomSelect incomplete escaping of dangerous characters in widget attributes
Low
Network
High
None
None
SummaryUser supplied values passed through to certain attributes in form widgets are not fully escaped for potentially dangerous tokens, and in some cases are rendered in browser as valid html tags. DetailsAttributes passed to the widget (such as For example, a label of: The actual output rendered in the browser for this example is: The script tags appears to be valid in Chrome dev tools, but doesn't appear execute code. ImpactAlthough the risk may be mediated since the content within the rendered Because of the relatively small number of users at this moment, our plan to yank affected releases on PyPI and GitHub, and because raw text is rendered but does not seem to be executable, I am marking the Severity Low. Update to version 5.3.3. The only difference from 5.3.2 is the code and documentation changes to resolve this vulnerability, so the update process should not be problematic. Affected versions
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.1b0
0.5.1b1
0.5.1b10
0.5.1b11
0.5.1b2
0.5.1b3
0.5.1b4
+ 19 more Show less
0.5.1b5
0.5.1b6
0.5.1b7
0.5.1b8
0.5.1b9
2024.12.1
2024.12.2
2024.12.3
2024.12.4
2024.12.5
2024.12.6
2024.12.7
2025.1.1
2025.1.2
2025.2.1
2025.2.2
2025.2.3
2025.3.1
2025.3.2
Fixed in
2025.3.3
References Updated Apr 06, 2025 · Source: OSV.dev | ||
0.5.1b6
pre
1 CVE
GHSA-785h-76cm-cpmf
Mar 26, 2025
Django TomSelect incomplete escaping of dangerous characters in widget attributes
Low
Network
High
None
None
SummaryUser supplied values passed through to certain attributes in form widgets are not fully escaped for potentially dangerous tokens, and in some cases are rendered in browser as valid html tags. DetailsAttributes passed to the widget (such as For example, a label of: The actual output rendered in the browser for this example is: The script tags appears to be valid in Chrome dev tools, but doesn't appear execute code. ImpactAlthough the risk may be mediated since the content within the rendered Because of the relatively small number of users at this moment, our plan to yank affected releases on PyPI and GitHub, and because raw text is rendered but does not seem to be executable, I am marking the Severity Low. Update to version 5.3.3. The only difference from 5.3.2 is the code and documentation changes to resolve this vulnerability, so the update process should not be problematic. Affected versions
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.1b0
0.5.1b1
0.5.1b10
0.5.1b11
0.5.1b2
0.5.1b3
0.5.1b4
+ 19 more Show less
0.5.1b5
0.5.1b6
0.5.1b7
0.5.1b8
0.5.1b9
2024.12.1
2024.12.2
2024.12.3
2024.12.4
2024.12.5
2024.12.6
2024.12.7
2025.1.1
2025.1.2
2025.2.1
2025.2.2
2025.2.3
2025.3.1
2025.3.2
Fixed in
2025.3.3
References Updated Apr 06, 2025 · Source: OSV.dev | ||
0.5.1b5
pre
1 CVE
GHSA-785h-76cm-cpmf
Mar 26, 2025
Django TomSelect incomplete escaping of dangerous characters in widget attributes
Low
Network
High
None
None
SummaryUser supplied values passed through to certain attributes in form widgets are not fully escaped for potentially dangerous tokens, and in some cases are rendered in browser as valid html tags. DetailsAttributes passed to the widget (such as For example, a label of: The actual output rendered in the browser for this example is: The script tags appears to be valid in Chrome dev tools, but doesn't appear execute code. ImpactAlthough the risk may be mediated since the content within the rendered Because of the relatively small number of users at this moment, our plan to yank affected releases on PyPI and GitHub, and because raw text is rendered but does not seem to be executable, I am marking the Severity Low. Update to version 5.3.3. The only difference from 5.3.2 is the code and documentation changes to resolve this vulnerability, so the update process should not be problematic. Affected versions
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.1b0
0.5.1b1
0.5.1b10
0.5.1b11
0.5.1b2
0.5.1b3
0.5.1b4
+ 19 more Show less
0.5.1b5
0.5.1b6
0.5.1b7
0.5.1b8
0.5.1b9
2024.12.1
2024.12.2
2024.12.3
2024.12.4
2024.12.5
2024.12.6
2024.12.7
2025.1.1
2025.1.2
2025.2.1
2025.2.2
2025.2.3
2025.3.1
2025.3.2
Fixed in
2025.3.3
References Updated Apr 06, 2025 · Source: OSV.dev | ||
0.5.1b4
pre
1 CVE
GHSA-785h-76cm-cpmf
Mar 26, 2025
Django TomSelect incomplete escaping of dangerous characters in widget attributes
Low
Network
High
None
None
SummaryUser supplied values passed through to certain attributes in form widgets are not fully escaped for potentially dangerous tokens, and in some cases are rendered in browser as valid html tags. DetailsAttributes passed to the widget (such as For example, a label of: The actual output rendered in the browser for this example is: The script tags appears to be valid in Chrome dev tools, but doesn't appear execute code. ImpactAlthough the risk may be mediated since the content within the rendered Because of the relatively small number of users at this moment, our plan to yank affected releases on PyPI and GitHub, and because raw text is rendered but does not seem to be executable, I am marking the Severity Low. Update to version 5.3.3. The only difference from 5.3.2 is the code and documentation changes to resolve this vulnerability, so the update process should not be problematic. Affected versions
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.1b0
0.5.1b1
0.5.1b10
0.5.1b11
0.5.1b2
0.5.1b3
0.5.1b4
+ 19 more Show less
0.5.1b5
0.5.1b6
0.5.1b7
0.5.1b8
0.5.1b9
2024.12.1
2024.12.2
2024.12.3
2024.12.4
2024.12.5
2024.12.6
2024.12.7
2025.1.1
2025.1.2
2025.2.1
2025.2.2
2025.2.3
2025.3.1
2025.3.2
Fixed in
2025.3.3
References Updated Apr 06, 2025 · Source: OSV.dev | ||
0.5.1b3
pre
1 CVE
GHSA-785h-76cm-cpmf
Mar 26, 2025
Django TomSelect incomplete escaping of dangerous characters in widget attributes
Low
Network
High
None
None
SummaryUser supplied values passed through to certain attributes in form widgets are not fully escaped for potentially dangerous tokens, and in some cases are rendered in browser as valid html tags. DetailsAttributes passed to the widget (such as For example, a label of: The actual output rendered in the browser for this example is: The script tags appears to be valid in Chrome dev tools, but doesn't appear execute code. ImpactAlthough the risk may be mediated since the content within the rendered Because of the relatively small number of users at this moment, our plan to yank affected releases on PyPI and GitHub, and because raw text is rendered but does not seem to be executable, I am marking the Severity Low. Update to version 5.3.3. The only difference from 5.3.2 is the code and documentation changes to resolve this vulnerability, so the update process should not be problematic. Affected versions
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.1b0
0.5.1b1
0.5.1b10
0.5.1b11
0.5.1b2
0.5.1b3
0.5.1b4
+ 19 more Show less
0.5.1b5
0.5.1b6
0.5.1b7
0.5.1b8
0.5.1b9
2024.12.1
2024.12.2
2024.12.3
2024.12.4
2024.12.5
2024.12.6
2024.12.7
2025.1.1
2025.1.2
2025.2.1
2025.2.2
2025.2.3
2025.3.1
2025.3.2
Fixed in
2025.3.3
References Updated Apr 06, 2025 · Source: OSV.dev | ||
0.5.1b2
pre
1 CVE
GHSA-785h-76cm-cpmf
Mar 26, 2025
Django TomSelect incomplete escaping of dangerous characters in widget attributes
Low
Network
High
None
None
SummaryUser supplied values passed through to certain attributes in form widgets are not fully escaped for potentially dangerous tokens, and in some cases are rendered in browser as valid html tags. DetailsAttributes passed to the widget (such as For example, a label of: The actual output rendered in the browser for this example is: The script tags appears to be valid in Chrome dev tools, but doesn't appear execute code. ImpactAlthough the risk may be mediated since the content within the rendered Because of the relatively small number of users at this moment, our plan to yank affected releases on PyPI and GitHub, and because raw text is rendered but does not seem to be executable, I am marking the Severity Low. Update to version 5.3.3. The only difference from 5.3.2 is the code and documentation changes to resolve this vulnerability, so the update process should not be problematic. Affected versions
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.1b0
0.5.1b1
0.5.1b10
0.5.1b11
0.5.1b2
0.5.1b3
0.5.1b4
+ 19 more Show less
0.5.1b5
0.5.1b6
0.5.1b7
0.5.1b8
0.5.1b9
2024.12.1
2024.12.2
2024.12.3
2024.12.4
2024.12.5
2024.12.6
2024.12.7
2025.1.1
2025.1.2
2025.2.1
2025.2.2
2025.2.3
2025.3.1
2025.3.2
Fixed in
2025.3.3
References Updated Apr 06, 2025 · Source: OSV.dev |