Medium severity5.9OSV Advisory· Published Jul 8, 2026· Updated Jul 9, 2026
CVE-2026-59924
CVE-2026-59924
Description
Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, Include.parse() joins and normalizes user-supplied include paths without verifying that the result remains within the intended markdown directory, allowing crafted include paths to access files outside that directory when markdown files are processed using md.read(). This issue is fixed in version 3.3.0.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
mistunePyPI | < 3.3.0 | 3.3.0 |
Affected products
4Patches
Vulnerability mechanics
References
6- github.com/lepture/mistune/commit/1bef343ade163fc3bb95572b15be720084cdb993nvdPatchWEB
- github.com/lepture/mistune/security/advisories/GHSA-r4rv-85jg-w4mfnvdExploitVendor AdvisoryWEB
- github.com/advisories/GHSA-r4rv-85jg-w4mfghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-59924ghsaADVISORY
- github.com/lepture/mistune/releases/tag/v3.3.0nvdRelease NotesWEB
- github.com/pypa/advisory-database/tree/main/vulns/mistune/PYSEC-2026-2212.yamlghsaWEB
News mentions
2- Mistune Project: Nine Vulnerabilities Including DoS and XSS Disclosed TogetherVypr Intelligence · Jul 9, 2026
- Authlib Mistune: Nine Vulnerabilities Including DoS and XSS Disclosed TogetherVypr Intelligence · Jul 9, 2026