CodeQL Alert #50: Reflected server-side cross-site scripting
| Field |
Value |
| Rule ID |
py/reflective-xss |
| Severity |
MEDIUM |
| File path |
vulnerable_xxe.py |
| Line range |
Lines 23–23 |
| CWE category |
CWE-079, CWE-116 |
| Classification |
demo-only |
| Priority tier |
batched |
| Alert link |
View CodeQL Alert |
Code Snippet
parser = etree.XMLParser()
doc = etree.fromstring(xml_content.encode(), parser)
return etree.tostring(doc).decode()
def parse_xml_file(filename):
tree = ET.parse(filename)
Classification: demo-only
This file is prefixed with vulnerable_ and is an intentionally insecure demo file for CodeQL demonstration purposes.
Generated by automated security triage on 2026-03-25.
CodeQL Alert #50: Reflected server-side cross-site scripting
py/reflective-xssvulnerable_xxe.pydemo-onlybatchedCode Snippet
Classification:
demo-onlyThis file is prefixed with
vulnerable_and is an intentionally insecure demo file for CodeQL demonstration purposes.Generated by automated security triage on 2026-03-25.