Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-59926

Опубликовано: 08 июл. 2026
Источник: redhat
CVSS3: 5.4

Описание

Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.2.1, render_admonition() in src/mistune/directives/admonition.py concatenates the Admonition directive :class: option into the HTML class attribute without escaping, allowing attribute injection and cross-site scripting even when HTMLRenderer escape mode is enabled. This issue is fixed in version 3.2.1.

A flaw was found in Mistune, a Python Markdown parser. The render_admonition() function in the Admonition directive concatenates user-controlled input into the HTML class attribute without proper escaping. This vulnerability allows for attribute injection and Cross-Site Scripting (XSS) attacks, even when the HTMLRenderer escape mode is enabled. A remote attacker could exploit this by providing specially crafted input, leading to the execution of arbitrary script code in the user's browser.

Отчет

This Moderate flaw in the Mistune Markdown parser allows for Cross-Site Scripting (XSS) due to improper sanitization of user-controlled input within the Admonition directive's class attribute. An attacker could exploit this by providing specially crafted Markdown content, leading to the execution of arbitrary script code in a user's browser when the content is rendered. This vulnerability requires user interaction with malicious content for successful exploitation.

Меры по смягчению последствий

To mitigate this issue, avoid processing untrusted or unvalidated Markdown content with affected versions of the Mistune library. Implement robust input validation and sanitization for any user-provided Markdown before rendering to prevent the injection of malicious attributes or scripts.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Migration Toolkit for Applications 8mta/mta-solution-server-rhel9Fix deferred
Red Hat OpenShift AI (RHOAI)rhoai/odh-pipeline-runtime-datascience-cpu-py312-rhel9Fix deferred
Red Hat OpenShift AI (RHOAI)rhoai/odh-pipeline-runtime-minimal-cpu-py312-rhel9Fix deferred
Red Hat OpenShift AI (RHOAI)rhoai/odh-pipeline-runtime-pytorch-cuda-py312-rhel9Fix deferred
Red Hat OpenShift AI (RHOAI)rhoai/odh-pipeline-runtime-pytorch-llmcompressor-cuda-py312-rhel9Fix deferred
Red Hat OpenShift AI (RHOAI)rhoai/odh-pipeline-runtime-pytorch-rocm-py312-rhel9Fix deferred
Red Hat OpenShift AI (RHOAI)rhoai/odh-pipeline-runtime-tensorflow-cuda-py312-rhel9Fix deferred
Red Hat OpenShift AI (RHOAI)rhoai/odh-pipeline-runtime-tensorflow-rocm-py312-rhel9Fix deferred
Red Hat OpenShift AI (RHOAI)rhoai/odh-th06-cpu-torch210-py312-rhel9Fix deferred
Red Hat OpenShift AI (RHOAI)rhoai/odh-th06-cpu-torch291-py312-rhel9Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=2498149mistune: Mistune: Cross-Site Scripting via unescaped HTML class attribute in Admonition directive

5.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.1
ubuntu
24 дня назад

Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.2.1, render_admonition() in src/mistune/directives/admonition.py concatenates the Admonition directive :class: option into the HTML class attribute without escaping, allowing attribute injection and cross-site scripting even when HTMLRenderer escape mode is enabled. This issue is fixed in version 3.2.1.

CVSS3: 6.1
nvd
24 дня назад

Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.2.1, render_admonition() in src/mistune/directives/admonition.py concatenates the Admonition directive :class: option into the HTML class attribute without escaping, allowing attribute injection and cross-site scripting even when HTMLRenderer escape mode is enabled. This issue is fixed in version 3.2.1.

msrc
22 дня назад

Mistune: XSS via unescaped class option in Admonition directive

CVSS3: 6.1
debian
24 дня назад

Mistune is a Python Markdown parser with renderers and plugins. Prior ...

github
12 дней назад

Mistune: XSS via unescaped class option in Admonition directive

5.4 Medium

CVSS3