CVE-2026-93421

Source
https://cve.org/CVERecord?id=CVE-2026-93421
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-93421.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-93421
Aliases
Published
2026-09-23T18:59:52Z
Modified
2026-09-24T03:45:17Z
Severity
  • 5.3 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N CVSS Calculator
Summary
Mesop: Unauthenticated ANSI Escape Sequence Injection in CSP Reporting Endpoint
Details

Mesop is a Python-based UI framework that allows users to build web applications. Prior to 1.3.4, the unauthenticated /csp endpoint passes attacker-controlled document-uri, blocked-uri, and violated-directive values to the csp_report handler in mesop/server/static_file_serving.py, which prints them to standard output without neutralizing terminal control sequences. When an operator views the resulting logs in an ANSI-capable terminal, injected ANSI or VT100 sequences can clear or reposition the display, hide text, or present forged messages, reducing the integrity of monitoring and incident-response output. This issue is fixed in version 1.3.4.

Database specific
{
    "cna_assigner":  "GitHub_M",
    "cwe_ids":  [
        "CWE-117",
        "CWE-150"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/93xxx/CVE-2026-93421.json"
}
References

Affected packages

Git / github.com/mesop-dev/mesop

Affected ranges

Type
GIT
Repo
https://github.com/mesop-dev/mesop
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "extracted_events":  [
        {
            "introduced":  "0"
        },
        {
            "fixed":  "1.3.4"
        }
    ],
    "source":  "AFFECTED_FIELD"
}

Affected versions

v0.*
v0.1
v0.10.0
v0.11.0
v0.11.1
v0.12.0
v0.12.1
v0.12.2
v0.12.3
v0.12.4
v0.12.5
v0.12.6
v0.12.7
v0.12.8
v0.12.9
v0.13.0
v0.14.0
v0.14.1
v0.14.2rc1
v0.14.2rc1-try2
v0.14.2rc1-try3
v0.2
v0.4.1
v0.4.2
v0.5
v0.5.3
v0.5.5
v0.5.6
v0.6.0
v0.7.1
v0.7.2
v0.8.0
v0.9.0
v0.9.1
v0.9.2
v0.9.3
v0.9.4
v0.9.5
v1.*
v1.0.0
v1.0.0rc1
v1.0.0rc2
v1.0.1
v1.0.1rc1
v1.1.0
v1.1.0rc1
v1.1.1
v1.1.1rc1
v1.1.1rc2
v1.1.1rc3
v1.2.0
v1.2.0rc1
v1.2.1
v1.2.1rc1
v1.2.2
v1.2.2rc1
v1.2.3
v1.2.4rc1
v1.2.5
v1.2.5c1
v1.2.6
v1.2.6rc1
v1.2.6rc2
v1.2.7
v1.2.7rc1
v1.3.0
v1.3.0rc1
v1.3.0rc2
v1.3.1
v1.3.2
v1.3.3

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-93421.json"