CVE-2025-53528: Fastapi Openapi Xss From Request

Unsanitized query or path parameters are incorporated into the `openapi_url` passed to `get_swagger_ui_html` or `get_redoc_html`. This can lead to Reflected Cross-Site Scripting (XSS) because the URL is embedded directly in a Javascript context without additional escaping. Sanitize the user input using `urllib.parse.quote` before generating the documentation

Provally CuratedPublic repositoryHighMedium confidenceVerifiedApache-2.0Python
greprules fetch cve-2025-53528-fastapi-openapi-xss-from-request --engine opengrep

Description

Unsanitized query or path parameters are incorporated into the `openapi_url` passed to `get_swagger_ui_html` or `get_redoc_html`. This can lead to Reflected Cross-Site Scripting (XSS) because the URL is embedded directly in a Javascript context without additional escaping. Sanitize the user input using `urllib.parse.quote` before generating the documentation