The serializer in html5lib before 0.99999999 might allow remote attackers to conduct cross-site scripting (XSS) attacks by leveraging mishandling of the < (less than) character in attribute values.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| html5lib(PyPI) | 0 | 0.999999999 | N/A |
CVSS Metrics