Project Subscriptions
No data.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-g7f6-rxc4-qhph | Mesop: Unauthenticated ANSI Escape Sequence Injection in CSP Reporting Endpoint |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 23 Sep 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 23 Sep 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Mesop is a Python-based UI framework that allows users to build web applications. Prior to 1.3.4, the unauthenticated /__csp__ endpoint passes attacker-controlled document-uri, blocked-uri, and violated-directive values to the csp_report handler in mesop/server/static_file_serving.py, which prints them to standard output without neutralizing terminal control sequences. When an operator views the resulting logs in an ANSI-capable terminal, injected ANSI or VT100 sequences can clear or reposition the display, hide text, or present forged messages, reducing the integrity of monitoring and incident-response output. This issue is fixed in version 1.3.4. | |
| Title | Mesop: Unauthenticated ANSI Escape Sequence Injection in CSP Reporting Endpoint | |
| Weaknesses | CWE-117 CWE-150 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-09-23T19:41:34.966Z
Reserved: 2026-09-17T20:57:18.984Z
Link: CVE-2026-93421
Updated: 2026-09-23T19:25:43.446Z
Status : Received
Published: 2026-09-23T19:19:45.140
Modified: 2026-09-23T20:17:22.503
Link: CVE-2026-93421
No data.
OpenCVE Enrichment
No data.
Github GHSA