MechanicalSoup is a Python library for automating interaction with websites, presenting a niche but specialized vulnerability surface centered on a single maintained package. The observed weakness class involves improper input validation in the library's web-parsing and form-handling mechanisms, reflecting the inherent challenges of safely processing untrusted HTML and user-supplied input at scale. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mechanicalsoup Project over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-34457HIGH MechanicalSoup is a Python library for automating interaction with websites. Starting in version 0.2.0 and prior to version 1.3.0, a malicious web server can read arbitrary files o | Jul 5, 2023 | 7.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mechanicalsoup Project.
Media articles that mention a CVE ID that affects a product developed by Mechanicalsoup Project — matched by CVE ID, not by vendor name.