Medium severity6.1OSV Advisory· Published Jul 8, 2026· Updated Jul 9, 2026
CVE-2026-59923
CVE-2026-59923
Description
Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, HTMLRenderer.safe_url() does not block percent-encoded javascript URIs, allowing attacker-supplied Markdown links or images to bypass URL protections and execute script in rendered HTML. This issue is fixed in version 3.3.0.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
mistunePyPI | < 3.3.0 | 3.3.0 |
Affected products
4Patches
Vulnerability mechanics
References
6- github.com/lepture/mistune/commit/c7101fcbb6e8790e8e39157c5ca2238fc6dd6cbcnvdPatchWEB
- github.com/lepture/mistune/security/advisories/GHSA-8c25-4j27-2rv3nvdExploitVendor AdvisoryWEB
- github.com/advisories/GHSA-8c25-4j27-2rv3ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-59923ghsaADVISORY
- github.com/lepture/mistune/releases/tag/v3.3.0nvdRelease NotesWEB
- github.com/pypa/advisory-database/tree/main/vulns/mistune/PYSEC-2026-2211.yamlghsaWEB
News mentions
2- Mistune Project: Nine Vulnerabilities Including DoS and XSS Disclosed TogetherVypr Intelligence · Jul 9, 2026
- Authlib Mistune: Nine Vulnerabilities Including DoS and XSS Disclosed TogetherVypr Intelligence · Jul 9, 2026