Safety vulnerability ID: 35030
The information on this page was manually curated by our Cybersecurity Intelligence Team.
Mistune.py in mistune 0.7.4 allows XSS via an unexpected newline (such as in java\nscript:) or a crafted email address, related to the escape and autolink functions. See CVE-2017-15612.
https://github.com/lepture/mistune/pull/140
Latest version: 3.0.2
A sane and fast Markdown parser with useful plugins and renderers
~~~~~~~~~~~
Released on Oct. 26, 2017
* Remove non breaking spaces preprocessing
* Remove rev and rel attribute for footnotes
* Fix bypassing XSS vulnerability by junorouse
This version is strongly recommended, since it fixed
a security issue.
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application