OVERVIEW CVE-2026-6019 is a cross-site scripting (XSS) vulnerability in the http.cookies.Morsel.js_output() function that fails to properly sanitize cookie values for HTML context. The flaw occurs because the function generates inline JavaScript code while only escaping double quotes for JavaScript string context, leaving the HTML-sensitive sequence </script> unfiltered. An attacker can exploit this to inject malicious scripts by crafting specially formatted cookie values that break out of the script element and execute arbitrary code in the user's browser. SEVERITY The vulnerability presents a moderate risk with a FAUCET Risk Score of 32.0/100. While specific CVSS metrics are not available, the XSS nature of this vulnerability typically involves a network attack vector that may require some user interaction. The base64 encoding mitigation suggests the vulnerability is exploitable through cookie value manipulation, with potential impact to confidentiality and integrity of affected user sessions. EXPLOITATION STATUS Currently, this vulnerability is not listed on the Known Exploited Vulnerabilities (KEV) catalog, indicating no confirmed active exploitation in the wild. However, it appears on the active Hot List, suggesting recent discovery or increased community attention. The extremely low EPSS score of 0.0004 indicates minimal likelihood of exploitation relative to other CVEs, though organizations should still apply available mitigations promptly as base64 encoding countermeasures indicate a practical fix is available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, < 3.13.14CPE match | cpe:2.3:a:python:python:*:*:*:*:*:*:*:* | ||
< 3.13.14CPE matchmatch criteria | cpe:2.3:a:python:python:*:*:*:*:*:*:*:* | ||
>= 3.14.0, <= 3.14.4CPE matchmatch criteria | cpe:2.3:a:python:python:*:*:*:*:*:*:*:* | ||
3.15.0CPE matchmatch criteria | cpe:2.3:a:python:python:3.15.0:alpha1:*:*:*:*:*:* | ||
3.15.0CPE matchmatch criteria | cpe:2.3:a:python:python:3.15.0:alpha2:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.