PatchSiren

woylie CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM woylie CVE published 2026-08-27

CVE-2026-66353

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in woylie doggo allows Reflected XSS. The vulnerability affects versions from 0.1.0 before 0.14.8 and is caused by the library's handling of date field values. Affected applications render <.field type='date'> over user-controlled params, allowing attackers to inject malicious code. The vulnerability can be [truncated]