Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-46338

Опубликовано: 16 июл. 2026
Источник: redhat
CVSS3: 4.3
EPSS Низкий

Описание

PyMdown Extensions is a set of extensions for the Python-Markdown markdown project. From 10.0.1 until 10.21.3, pymdownx.snippets uses a string-prefix containment check in SnippetPreprocessor.get_snippet_path() in pymdownx/snippets.py when restrict_base_path: True, allowing markdown snippet directives to read files from sibling paths that share the same base_path prefix, such as docs and docs_internal. This is a regression of CVE-2023-32309. This issue is fixed in version 10.21.3.

A flaw was found in PyMdown Extensions, a tool used for processing Markdown documents. This vulnerability allows an attacker to potentially read sensitive files from unexpected locations on a system. By crafting a special Markdown snippet, an attacker could trick the system into accessing files outside of the intended directory, leading to unauthorized information disclosure. This issue requires user interaction, meaning a user would need to process a malicious Markdown file for the attack to succeed.

Отчет

Red Hat ships pymdown-extensions in several products as a bundled dependency. The vulnerability requires an attacker to control Markdown content processed by the pymdownx.snippets extension and for sibling directories with a matching path prefix to exist. While the vulnerable versions are present, the practical exploitability depends on whether untrusted Markdown input is processed in the affected products.

Меры по смягчению последствий

Ensure that untrusted Markdown content is not processed by the pymdownx.snippets extension. If the snippets feature is not required, it can be disabled in the MkDocs or Python-Markdown configuration.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Developer Hubrhdh/rhdh-hub-rhel9Fix deferred
Red Hat Hardened ImagestrivyNot affected
Red Hat OpenShift Container Platform 4openshift4/ose-olm-catalogd-rhel9Fix deferred
Self-service automation portal 2ansible-automation-platform/bootc-automation-portal-rhel9Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-22
https://bugzilla.redhat.com/show_bug.cgi?id=2501448pymdown-extensions: PyMdown Extensions: Information disclosure via crafted Markdown snippets

EPSS

Процентиль: 23%
0.0031
Низкий

4.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.3
ubuntu
21 день назад

PyMdown Extensions is a set of extensions for the Python-Markdown markdown project. From 10.0.1 until 10.21.3, pymdownx.snippets uses a string-prefix containment check in SnippetPreprocessor.get_snippet_path() in pymdownx/snippets.py when `restrict_base_path: True`, allowing markdown snippet directives to read files from sibling paths that share the same base_path prefix, such as docs and docs_internal. This is a regression of CVE-2023-32309. This issue is fixed in version 10.21.3.

CVSS3: 4.3
nvd
21 день назад

PyMdown Extensions is a set of extensions for the Python-Markdown markdown project. From 10.0.1 until 10.21.3, pymdownx.snippets uses a string-prefix containment check in SnippetPreprocessor.get_snippet_path() in pymdownx/snippets.py when `restrict_base_path: True`, allowing markdown snippet directives to read files from sibling paths that share the same base_path prefix, such as docs and docs_internal. This is a regression of CVE-2023-32309. This issue is fixed in version 10.21.3.

CVSS3: 4.3
debian
21 день назад

PyMdown Extensions is a set of extensions for the Python-Markdown mark ...

CVSS3: 4.3
github
3 месяца назад

Regression in pymdownx.snippets reintroduces sibling-prefix path traversal bypass despite restrict_base_path

EPSS

Процентиль: 23%
0.0031
Низкий

4.3 Medium

CVSS3