Skip to content

[CodeQL #33] XML internal entity expansion #35

Description

@devin-ai-integration

CodeQL Alert #33: XML internal entity expansion

Field Value
Alert Number #33
Rule ID py/xml-bomb
Severity HIGH
File vulnerable_xxe.py
Line 50
CWE CWE-400, CWE-776
Classification demo-only
Alert Link View CodeQL Alert

Description

XML internal entity expansion

Classification: demo-only

This file is prefixed with vulnerable_ and is an intentionally insecure demo file for CodeQL demonstration purposes.


Generated by automated security triage on 2026-03-25.

Metadata

Metadata

Assignees

No one assigned

    Labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions