Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 8

Количество 8

ubuntu логотип

CVE-2026-44896

2 месяца назад

Mistune is a Python Markdown parser with renderers and plugins. In 3.2.0 and earlier, in src/mistune/directives/image.py, the render_figure() function concatenates figclass and figwidth options directly into HTML attributes without escaping. This allows attribute injection and XSS even when HTMLRenderer(escape=True) is used, because these values bypass the inline renderer. Version 3.2.1 contains a patch.

CVSS3: 6.1
EPSS: Низкий
redhat логотип

CVE-2026-44896

2 месяца назад

Mistune is a Python Markdown parser with renderers and plugins. In 3.2.0 and earlier, in src/mistune/directives/image.py, the render_figure() function concatenates figclass and figwidth options directly into HTML attributes without escaping. This allows attribute injection and XSS even when HTMLRenderer(escape=True) is used, because these values bypass the inline renderer. Version 3.2.1 contains a patch.

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2026-44896

2 месяца назад

Mistune is a Python Markdown parser with renderers and plugins. In 3.2.0 and earlier, in src/mistune/directives/image.py, the render_figure() function concatenates figclass and figwidth options directly into HTML attributes without escaping. This allows attribute injection and XSS even when HTMLRenderer(escape=True) is used, because these values bypass the inline renderer. Version 3.2.1 contains a patch.

CVSS3: 6.1
EPSS: Низкий
msrc логотип

CVE-2026-44896

2 месяца назад

Mistune: XSS via unescaped figclass/figwidth in Figure directive

EPSS: Низкий
debian логотип

CVE-2026-44896

2 месяца назад

Mistune is a Python Markdown parser with renderers and plugins. In 3.2 ...

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-58cw-g322-p94v

3 месяца назад

Mistune has XSS via unescaped figclass/figwidth in Figure directive

CVSS3: 6.1
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20827-1

2 месяца назад

Security update for python-mistune

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:21339-1

23 дня назад

Security update for python-mistune

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-44896

Mistune is a Python Markdown parser with renderers and plugins. In 3.2.0 and earlier, in src/mistune/directives/image.py, the render_figure() function concatenates figclass and figwidth options directly into HTML attributes without escaping. This allows attribute injection and XSS even when HTMLRenderer(escape=True) is used, because these values bypass the inline renderer. Version 3.2.1 contains a patch.

CVSS3: 6.1
0%
Низкий
2 месяца назад
redhat логотип
CVE-2026-44896

Mistune is a Python Markdown parser with renderers and plugins. In 3.2.0 and earlier, in src/mistune/directives/image.py, the render_figure() function concatenates figclass and figwidth options directly into HTML attributes without escaping. This allows attribute injection and XSS even when HTMLRenderer(escape=True) is used, because these values bypass the inline renderer. Version 3.2.1 contains a patch.

CVSS3: 5.4
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-44896

Mistune is a Python Markdown parser with renderers and plugins. In 3.2.0 and earlier, in src/mistune/directives/image.py, the render_figure() function concatenates figclass and figwidth options directly into HTML attributes without escaping. This allows attribute injection and XSS even when HTMLRenderer(escape=True) is used, because these values bypass the inline renderer. Version 3.2.1 contains a patch.

CVSS3: 6.1
0%
Низкий
2 месяца назад
msrc логотип
CVE-2026-44896

Mistune: XSS via unescaped figclass/figwidth in Figure directive

0%
Низкий
2 месяца назад
debian логотип
CVE-2026-44896

Mistune is a Python Markdown parser with renderers and plugins. In 3.2 ...

CVSS3: 6.1
0%
Низкий
2 месяца назад
github логотип
GHSA-58cw-g322-p94v

Mistune has XSS via unescaped figclass/figwidth in Figure directive

CVSS3: 6.1
0%
Низкий
3 месяца назад
suse-cvrf логотип
openSUSE-SU-2026:20827-1

Security update for python-mistune

2 месяца назад
suse-cvrf логотип
openSUSE-SU-2026:21339-1

Security update for python-mistune

23 дня назад

Уязвимостей на страницу