A XSS vulnerability was discovered in python-lxml\'s clean module. The module\'s parser didn\'t properly imitate browsers, which caused different behaviors between the sanitizer and the user\'s page. A remote attacker could exploit this flaw to run arbitrary HTML/JS code.