Open-Source Security Intelligence

Know every vulnerability
before it knows you.

DevGuard continuously monitors your dependencies and alerts you when CVEs like this one affect your stack — with real-time threat intelligence built for developers.

Search

PYSEC-2026-4105

MediumCVSS 5.3 / 10
Published Oct 1, 2026·Last modified Oct 1, 2026
Affected Components(1)
PyPI logomesop
< 1.3.4
Description

Summary

The /__csp__ endpoint accepts unauthenticated JSON reports and logs user-controlled values directly to stdout using print() without escaping control characters.

A remote attacker can include ANSI/VT100 escape sequences in fields such as blocked-uri or document-uri. When the logs are viewed in an ANSI-capable terminal, these sequences can manipulate the displayed output (e.g., clear the screen, hide text, or inject misleading messages), affecting the integrity of operator-facing logs.

Details

The CSP reporting endpoint accepts arbitrary JSON and prints several request fields directly:

mesop/server/static_file_serving.py

@app.route(prefix_base_url("/__csp__"), methods=["POST"])
def csp_report():
    report = request.get_json(force=True)

    document_uri = report["csp-report"]["document-uri"]
    blocked_uri = report["csp-report"]["blocked-uri"]
    violated_directive = report["csp-report"]["violated-directive"]

    print(f"... Blocked URL: {blocked_uri} ...")

Since these values are written to stdout without sanitization, ANSI escape sequences supplied by a remote client are preserved and interpreted by ANSI-compatible terminals.

PoC

Send the following request:

POST /__csp__
Content-Type: application/json

{
  "csp-report": {
    "document-uri": "https://victim.example",
    "blocked-uri": "\u001b[2J\u001b[H\u001b[32m*** SECURITY OK - No CSP violations found ***\u001b[0m\n\u001b[8mhttps://evil.example",
    "violated-directive": "script-src-elem"
  }
}

The request is accepted (HTTP 204), and the injected escape sequences are written to stdout unchanged.

When the captured output is rendered in a VT100-compatible terminal (verified using pyte), the original CSP warning is visually replaced with attacker-controlled content.

Expected output

    Content Security Policy Error

Directive: script-src-elem
Blocked URL: ...
App path: /app

Rendered output

*** SECURITY OK - No CSP violations found ***
https://evil.example
App path: /app

Impact

An unauthenticated remote attacker can submit a crafted request to the /csp endpoint containing ANSI/VT100 escape sequences. Because these values are written directly to stdout without sanitization, an attacker can:

  1. Inject forged log messages that appear to originate from the application.
  2. Manipulate the terminal display by clearing the screen, moving the cursor, or overwriting previously displayed log output.
  3. Hide or disguise security-relevant log entries using terminal formatting sequences such as colors, hidden text, or cursor positioning.
  4. Mislead administrators during monitoring or incident response by displaying attacker-controlled messages (e.g., fake "SECURITY OK" notifications).
  5. Reduce the integrity and trustworthiness of operator-facing logs, making troubleshooting and security investigations less reliable.
Upload your SBOM

Upload your own SBOM in CycloneDX 1.6 or higher (JSON) directly here to check your vulnerabilities.

Risk Scores
Base Score
5.3

The vulnerability can be exploited over the network without needing physical access. It is easy for an attacker to exploit this vulnerability. An attacker does not need any special privileges or access rights.

Threat Intelligence
1.3

Limited exploitation activity has been observed. Close monitoring and planned remediation are recommended.

EPSS
0.40%

The exploit probability is very low. The vulnerability is unlikely to be exploited in the next 30 days.

Exploit
Not available

We did not find any exploit available. Neither in GitHub repositories nor in the Exploit-Database.

Browse More

Scan your project

Continuously monitor your dependencies and get alerted when vulnerabilities like this one affect your stack.

Checkout DevGuard