lxml 4.6.2 allows XSS. It places the HTML action attribute into defs.link_attrs (in html/defs.py) for later use in input sanitization, but does not do the same for the HTML5 formaction attribute. CREATE(Triage):(User=admin) [CVE-2021-28957|https://nvd.nist.gov/vuln/detail/CVE-2021-28957]