Safety vulnerability ID: 38198
The information on this page was manually curated by our Cybersecurity Intelligence Team.
python-markdown2 through 2.3.8 allows XSS because element names are mishandled unless a \w+ match succeeds. For example, an attack might use elementname@ or elementname- with an onclick attribute.
Latest version: 2.5.1
A fast and complete Python implementation of Markdown
python-markdown2 through 2.3.8 allows XSS because element names are mishandled unless a \w+ match succeeds. For example, an attack might use elementname@ or elementname- with an onclick attribute.
MISC:https://github.com/trentm/python-markdown2/issues/348: https://github.com/trentm/python-markdown2/issues/348
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application