PT-2026-56511 · Pypi · Mistune

·

CVE-2026-59926

·

Published

2026-07-08

·

Updated

2026-07-20

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Mistune versions prior to 3.2.1
Description The render admonition() function in src/mistune/directives/admonition.py concatenates the :class: option of the Admonition directive into the HTML class attribute without proper escaping. This allows for attribute injection and cross-site scripting (XSS), a technique where malicious scripts are injected into trusted websites, even when the HTMLRenderer escape mode is active.
Recommendations Update to version 3.2.1.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-92214
CVE-2026-59926
ECHO-4C0D-898E-3E31
GHSA-G97X-GVCM-X72H
OPENSUSE-SU-2026:21339-1
PYSEC-2026-2214
SUSE-SU-2026:22655-1

Affected Products

Mistune