Medium severity6.1NVD Advisory· Published Jan 18, 2018· Updated Jun 17, 2026
CVE-2018-5773
CVE-2018-5773
Description
An issue was discovered in markdown2 (aka python-markdown2) through 2.3.5. The safe_mode feature, which is supposed to sanitize user input against XSS, is flawed and does not escape the input properly. With a crafted payload, XSS can be triggered, as demonstrated by omitting the final '>' character from an IMG tag.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
markdown2PyPI | < 2.3.6 | 2.3.6 |
Affected products
3- osv-coords2 versions
< 2.4.0-2.4+ 1 more
- (no CPE)range: < 2.4.0-2.4
- (no CPE)range: < 2.3.6
- cpe:2.3:a:python-markdown2_project:python-markdown2:*:*:*:*:*:*:*:*Range: <=2.3.5
Patches
Vulnerability mechanics
References
8- github.com/advisories/GHSA-p6h9-gw49-rqm4ghsaADVISORY
- github.com/trentm/python-markdown2/issues/285nvdThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2018-5773ghsaADVISORY
- github.com/google/osv/issues/430ghsaWEB
- github.com/pypa/advisory-database/tree/main/vulns/markdown2/PYSEC-2018-13.yamlghsaWEB
- github.com/trentm/python-markdown2/blob/master/CHANGES.mdghsaWEB
- github.com/trentm/python-markdown2/commit/1b1dcdd727c0ef03453b9f5ef5ae3679f1d72323ghsaWEB
- github.com/trentm/python-markdown2/pull/303ghsaWEB
News mentions
0No linked articles in our index yet.