Openpyxl 2.4.1 resolves external entities by default, which allows remote attackers to conduct XXE attacks via a crafted .xlsx document.
2017-02-15T19:59:01.283
2025-04-20T01:37:25.860
Deferred
CVSSv3.0: 8.2 (HIGH)
AV:N/AC:M/Au:N/C:P/I:N/A:P
8.6
4.9