VYPR
Medium severity6.1OSV Advisory· Published Jul 8, 2026· Updated Jul 9, 2026

CVE-2026-59923

CVE-2026-59923

Description

Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, HTMLRenderer.safe_url() does not block percent-encoded javascript URIs, allowing attacker-supplied Markdown links or images to bypass URL protections and execute script in rendered HTML. This issue is fixed in version 3.3.0.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
mistunePyPI
< 3.3.03.3.0

Affected products

4

Patches

Vulnerability mechanics

References

6

News mentions

2