bandit1.7.0

S317 Using {name} to parse untrusted XML data is known to be vulnerable to XML attacks. Replace {name} with its defusedxml equivalent function or make sure defusedxml.defuse_stdlib() is called

  • xml.sax.parse
  • xml.sax.parseString
  • xml.sax.make_parser