Incomplete blacklist vulnerability in the lxml.html.clean module in lxml before 3.3.5 allows remote attackers to conduct cross-site scripting (XSS) attacks via control characters in the link scheme to the clean_html function.Per: http://cwe.mitre.org/data/definitions/184.html CWE-184: Incomplete Blacklist http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-3146