CodeQL Alert #33: XML internal entity expansion
| Field |
Value |
| Alert Number |
#33 |
| Rule ID |
py/xml-bomb |
| Severity |
HIGH |
| File |
vulnerable_xxe.py |
| Line |
50 |
| CWE |
CWE-400, CWE-776 |
| Classification |
demo-only |
| Alert Link |
View CodeQL Alert |
Description
XML internal entity expansion
Classification: demo-only
This file is prefixed with vulnerable_ and is an intentionally insecure demo file for CodeQL demonstration purposes.
Generated by automated security triage on 2026-03-25.
CodeQL Alert #33: XML internal entity expansion
py/xml-bombvulnerable_xxe.pydemo-onlyDescription
XML internal entity expansion
Classification:
demo-onlyThis file is prefixed with
vulnerable_and is an intentionally insecure demo file for CodeQL demonstration purposes.Generated by automated security triage on 2026-03-25.