bandit1.7.0

S316 Using {name} to parse untrusted XML data is known to be vulnerable to XML attacks. Replace {name} with its defusedxml equivalent function or make sure defusedxml.defuse_stdlib() is called

  • xml.dom.expatbuilder.parse
  • xml.dom.expatbuilder.parseString