PT-2026-56513 · Pypi · Mistune

·

CVE-2026-59930

·

Published

2026-07-08

·

Updated

2026-07-20

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Mistune versions prior to 3.3.0
Description The toc plugin and TableOfContents directive generate heading IDs using predictable toc N values instead of slugifying the heading text. This allows attacker-controlled content with id="toc N" to collide with generated anchors, which can redirect same-page navigation, CSS selectors, or JavaScript handlers.
Recommendations Update to version 3.3.0.

Exploit

Fix

Insufficient Verification of Data Authenticity

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-92223
CVE-2026-59930
ECHO-1288-EBEC-BB75
GHSA-2HM2-HC3V-44H9
OPENSUSE-SU-2026:21339-1
PYSEC-2026-2218
SUSE-SU-2026:22655-1

Affected Products

Mistune