Skip to content

fix: upgrade lxml to 6.1.0 (CVE-2026-41066)#887

Open
orbisai0security wants to merge 1 commit into
NanmiCoder:mainfrom
orbisai0security:fix-cve-2026-41066-lxml
Open

fix: upgrade lxml to 6.1.0 (CVE-2026-41066)#887
orbisai0security wants to merge 1 commit into
NanmiCoder:mainfrom
orbisai0security:fix-cve-2026-41066-lxml

Conversation

@orbisai0security
Copy link
Copy Markdown
Contributor

Summary

Upgrade lxml from 6.0.0 to 6.1.0 to fix CVE-2026-41066.

Vulnerability

Field Value
ID CVE-2026-41066
Severity HIGH
Scanner trivy
Rule CVE-2026-41066
File uv.lock

Description: lxml: python: lxml: Information disclosure via untrusted XML input leading to local file read

Changes

  • requirements.txt

Verification

  • Build passes
  • Scanner re-scan confirms fix
  • LLM code review passed

Automated security fix by OrbisAI Security

Automated dependency upgrade by Orbis Security AI
@dosubot dosubot Bot added size:XS This PR changes 0-9 lines, ignoring generated files. bug Something isn't working labels May 5, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working size:XS This PR changes 0-9 lines, ignoring generated files.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant