Количество 8
Количество 8
CVE-2026-44896
Mistune is a Python Markdown parser with renderers and plugins. In 3.2.0 and earlier, in src/mistune/directives/image.py, the render_figure() function concatenates figclass and figwidth options directly into HTML attributes without escaping. This allows attribute injection and XSS even when HTMLRenderer(escape=True) is used, because these values bypass the inline renderer. Version 3.2.1 contains a patch.
CVE-2026-44896
Mistune is a Python Markdown parser with renderers and plugins. In 3.2.0 and earlier, in src/mistune/directives/image.py, the render_figure() function concatenates figclass and figwidth options directly into HTML attributes without escaping. This allows attribute injection and XSS even when HTMLRenderer(escape=True) is used, because these values bypass the inline renderer. Version 3.2.1 contains a patch.
CVE-2026-44896
Mistune is a Python Markdown parser with renderers and plugins. In 3.2.0 and earlier, in src/mistune/directives/image.py, the render_figure() function concatenates figclass and figwidth options directly into HTML attributes without escaping. This allows attribute injection and XSS even when HTMLRenderer(escape=True) is used, because these values bypass the inline renderer. Version 3.2.1 contains a patch.
CVE-2026-44896
Mistune: XSS via unescaped figclass/figwidth in Figure directive
CVE-2026-44896
Mistune is a Python Markdown parser with renderers and plugins. In 3.2 ...
GHSA-58cw-g322-p94v
Mistune has XSS via unescaped figclass/figwidth in Figure directive
openSUSE-SU-2026:20827-1
Security update for python-mistune
openSUSE-SU-2026:21339-1
Security update for python-mistune
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-44896 Mistune is a Python Markdown parser with renderers and plugins. In 3.2.0 and earlier, in src/mistune/directives/image.py, the render_figure() function concatenates figclass and figwidth options directly into HTML attributes without escaping. This allows attribute injection and XSS even when HTMLRenderer(escape=True) is used, because these values bypass the inline renderer. Version 3.2.1 contains a patch. | CVSS3: 6.1 | 0% Низкий | 2 месяца назад | |
CVE-2026-44896 Mistune is a Python Markdown parser with renderers and plugins. In 3.2.0 and earlier, in src/mistune/directives/image.py, the render_figure() function concatenates figclass and figwidth options directly into HTML attributes without escaping. This allows attribute injection and XSS even when HTMLRenderer(escape=True) is used, because these values bypass the inline renderer. Version 3.2.1 contains a patch. | CVSS3: 5.4 | 0% Низкий | 2 месяца назад | |
CVE-2026-44896 Mistune is a Python Markdown parser with renderers and plugins. In 3.2.0 and earlier, in src/mistune/directives/image.py, the render_figure() function concatenates figclass and figwidth options directly into HTML attributes without escaping. This allows attribute injection and XSS even when HTMLRenderer(escape=True) is used, because these values bypass the inline renderer. Version 3.2.1 contains a patch. | CVSS3: 6.1 | 0% Низкий | 2 месяца назад | |
CVE-2026-44896 Mistune: XSS via unescaped figclass/figwidth in Figure directive | 0% Низкий | 2 месяца назад | ||
CVE-2026-44896 Mistune is a Python Markdown parser with renderers and plugins. In 3.2 ... | CVSS3: 6.1 | 0% Низкий | 2 месяца назад | |
GHSA-58cw-g322-p94v Mistune has XSS via unescaped figclass/figwidth in Figure directive | CVSS3: 6.1 | 0% Низкий | 3 месяца назад | |
openSUSE-SU-2026:20827-1 Security update for python-mistune | 2 месяца назад | |||
openSUSE-SU-2026:21339-1 Security update for python-mistune | 23 дня назад |
Уязвимостей на страницу