---
id: CVE-2023-40024
aliases:
  - GHSA-6xcx-gx7r-rccj
  - PYSEC-2026-1905
title: Scancode.io Reflected Cross-Site Scripting (XSS) in license endpoint
summary: Scancode.io Reflected Cross-Site Scripting (XSS) in license endpoint
severity: medium
cvss: 6.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'
vendor: scancodeio
product: scancodeio
ecosystem: pip
affected:
  - scancodeio < 32.5.2
patched:
  - scancodeio 32.5.2
published: '2023-08-15'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T03:49:57.536585679Z'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-6xcx-gx7r-rccj'
references:
  - url: >-
      https://github.com/nexB/scancode.io/security/advisories/GHSA-6xcx-gx7r-rccj
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2023-40024'
  - url: 'https://github.com/nexB/scancode.io'
  - url: >-
      https://github.com/nexB/scancode.io/blob/dd7769fbc97c84545579cebf1dc4838214098a11/CHANGELOG.rst#v3252-2023-08-14
  - url: 'https://github.com/nexB/scancode.io/releases/tag/v32.5.2'
tags:
  - osv
  - pip
epss: 0.00506
epssPercentile: 0.40564
ingestedAt: '2026-07-08T18:25:46.558Z'
---

## Overview

### Summary
In the `/license/` endpoint, the detailed view key is not properly validated and sanitized, which can result in a potential cross-site scripting (XSS) vulnerability when attempting to access a detailed license view that does not exist.

### Details
In the `/license/` endpoint, the `license_details_view` function is vulnerable to a potential cross-site scripting (XSS) attack due to inadequate validation and sanitization of the `key` parameter. This vulnerability arises when attempting to access a key with malicious javascript.

```python
def license_details_view(request, key):
    """
    Display all available information about a given license `key` followed by
    the full license text.
    """
    licenses = get_licenses()
    try:
        data = saneyaml.dump(licenses[key].to_dict())
        text = licenses[key].text
    except KeyError:
        return HttpResponseNotFound(f"License {key} not found.") # Leads to cross-site scripting when key is malicious javascript
    return HttpResponse(f"<pre>{data}</pre><hr><pre>{text}</pre>")
```


### PoC
1. Access following endpoint on scancode.io instance: http://localhost/license/%3Cscript%3Ealert(document.cookie);%3C/script%3E/

### Impact
Attackers can exploit the vulnerability to inject malicious scripts into the response generated by the `license_details_view` function. When unsuspecting users visit the page, their browsers will execute the injected scripts, leading to unauthorized actions, session hijacking, or stealing sensitive information.


## Affected packages

- `scancodeio < 32.5.2`

## Remediation

Upgrade to a patched release:

- `scancodeio 32.5.2`
