---
id: CVE-2022-4396
aliases:
  - GHSA-894q-wpg5-mf2h
  - PYSEC-2026-910
title: pyRdfa3 Cross-site Scripting vulnerability
summary: pyRdfa3 Cross-site Scripting vulnerability
severity: medium
cvss: 5.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'
vendor: pyrdfa3
product: pyrdfa3
ecosystem: pip
affected:
  - pyrdfa3 < 3.6.2
patched:
  - pyrdfa3 3.6.2
published: '2022-12-10'
updated: '2026-07-07'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-894q-wpg5-mf2h'
references:
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2022-4396'
  - url: 'https://github.com/RDFLib/pyrdfa3/issues/38'
  - url: 'https://github.com/RDFLib/pyrdfa3/pull/40'
  - url: >-
      https://github.com/RDFLib/pyrdfa3/commit/ffd1d62dd50d5f4190013b39cedcdfbd81f3ce3e
  - url: 'https://github.com/RDFLib/pyrdfa3'
  - url: 'https://vuldb.com/?id.215249'
tags:
  - osv
  - pip
epss: 0.0059
epssPercentile: 0.46941
ingestedAt: '2026-07-08T18:25:47.336Z'
---

## Overview

A vulnerability was found in RDFlib pyrdfa3 and classified as problematic. This issue affects the function `_get_option` of the file `pyRdfa/__init__.py`. The manipulation leads to cross site scripting. The attack may be initiated remotely. The name of the patch is ffd1d62dd50d5f4190013b39cedcdfbd81f3ce3e. It is recommended to apply a patch to fix this issue. The identifier VDB-215249 was assigned to this vulnerability.

## Affected packages

- `pyrdfa3 < 3.6.2`

## Remediation

Upgrade to a patched release:

- `pyrdfa3 3.6.2`
