py3-lxml: missing input sanitization for formaction HTML5 attributes may lead to XSS (CVE-2021-28957)
lxml 4.6.2 allows XSS. It places the HTML action attribute into defs.link_attrs (in html/defs.py) for later use in input sanitization, but does not do the same for the HTML5 formaction attribute.
Fixed In Version:
- master (1beaaca1)
To upload designs, you'll need to enable LFS and have an admin enable hashed storage. More information