id: PYSEC-2019-26 details: invenio-previewer before 1.0.0a12 allows XSS. affected: - package: name: invenio-previewer ecosystem: PyPI purl: pkg:pypi/invenio-previewer ranges: - type: ECOSYSTEM events: - introduced: "0" - fixed: 1.0.0a12 versions: - 0.1.0 - 1.0.0a2 - 1.0.0a3 - 1.0.0a4 - 1.0.0a5 - 1.0.0a6 - 1.0.0a7 - 1.0.0a8 - 1.0.0a9 - 1.0.0a10 - 1.0.0a11 references: - type: ADVISORY url: https://github.com/inveniosoftware/invenio-previewer/security/advisories/GHSA-j9m2-6hq2-4r3c aliases: - CVE-2019-1020019 - GHSA-j9m2-6hq2-4r3c modified: "2019-07-31T19:44:00Z" published: "2019-07-29T14:15:00Z"