Safety vulnerability ID: 38198
The information on this page was manually curated by our Cybersecurity Intelligence Team.
[This advisory has been limited. Please create a free account to view the full advisory.]
Latest version: 2.5.4
A fast and complete Python implementation of Markdown
[This affected versions has been limited. Please create a free account to view the full affected versions.]
[This fixed versions has been limited. Please create a free account to view the full fixed versions.]
python-markdown2 through 2.3.8 allows XSS because element names are mishandled unless a \w+ match succeeds. For example, an attack might use elementname@ or elementname- with an onclick attribute.
MISC:https://github.com/trentm/python-markdown2/issues/348: https://github.com/trentm/python-markdown2/issues/348
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application