nyx/tests/fixtures/xxe/python/unsafe_xxe.py

9 lines
249 B
Python
Raw Permalink Normal View History

2026-05-07 01:29:31 -04:00
# Unsafe: tainted XML reaches xml.sax.parseString, which is XXE-vulnerable
# by default in Python's stdlib.
import xml.sax
from flask import request
def handle():
body = request.args.get("xml")
return xml.sax.parseString(body, MyHandler())