PatchSiren

Jazzband CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Jazzband CVE published 2026-08-12

CVE-2026-9318

CVE-2026-9318 is a stored cross-site scripting vulnerability in the HTML export functionality of tablib versions prior to 3.10.0. The vulnerability allows attackers to execute arbitrary JavaScript by embedding malicious payloads in dataset titles, which are interpolated unsanitized into HTML output. This issue can lead to session hijacking, unauthorized administrative actions, and sensitive data exposure [truncated]