id: PYSEC-2026-1253 published: "2026-07-07T14:34:39.171194Z" modified: "2026-07-07T17:23:55.061714Z" aliases: - CVE-2024-41675 - GHSA-r3jc-vhf4-6v32 summary: CKAN has Cross-site Scripting vector in the Datatables view plugin details: "The [Datatables view plugin](https://docs.ckan.org/en/2.10/maintaining/data-viewer.html#datatables-view) did not properly escape record data coming from the DataStore, leading to a potential XSS vector.\n\n\n### Impact\nSites running CKAN >= 2.7.0 with the `datatables_view` plugin activated. This is a plugin included in CKAN core, that not activated by default but it is widely used to preview tabular data.\n\n### Patches\nThis vulnerability has been fixed in CKAN 2.10.5 and 2.11.0\n\n### Workarounds\nPrevent importing of tabular files to the DataStore via DataPusher, XLoader,etc, at least those published from untrusted sources.\n" affected: - package: name: ckan ecosystem: PyPI purl: pkg:pypi/ckan ranges: - type: ECOSYSTEM events: - introduced: 2.7.0 - fixed: 2.10.5 versions: - 2.10.0 - 2.10.1 - 2.10.3 - 2.10.4 - 2.7.0 - 2.7.1 - 2.7.10 - 2.7.11 - 2.7.12 - 2.7.2 - 2.7.3 - 2.7.4 - 2.7.5 - 2.7.6 - 2.7.7 - 2.7.8 - 2.7.9 - 2.8.0 - 2.8.1 - 2.8.10 - 2.8.11 - 2.8.12 - 2.8.2 - 2.8.3 - 2.8.4 - 2.8.5 - 2.8.6 - 2.8.7 - 2.8.8 - 2.8.9 - 2.9.0 - 2.9.1 - 2.9.10 - 2.9.11 - 2.9.2 - 2.9.3 - 2.9.4 - 2.9.5 - 2.9.6 - 2.9.7 - 2.9.8 - 2.9.9 references: - type: WEB url: https://github.com/ckan/ckan/security/advisories/GHSA-r3jc-vhf4-6v32 - type: ADVISORY url: https://nvd.nist.gov/vuln/detail/CVE-2024-41675 - type: WEB url: https://github.com/ckan/ckan/commit/9e89ce8220ab1445e0bd85a67994a51d9d3d2688 - type: WEB url: https://github.com/ckan/ckan/commit/d7dfe8c427b1c63c75d788a609f3b7d7620a25a1 - type: PACKAGE url: https://github.com/ckan/ckan - type: PACKAGE url: https://pypi.org/project/ckan - type: ADVISORY url: https://github.com/advisories/GHSA-r3jc-vhf4-6v32 severity: - type: CVSS_V3 score: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N - type: CVSS_V4 score: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N