CVE-2026-59924

Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, Include.parse() joins and normalizes user-supplied include paths without verifying that the result remains within the intended markdown directory, allowing crafted include paths to access files outside that directory when markdown files are processed using md.read(). This issue is fixed in version 3.3.0.
Configurations

Configuration 1 (hide)

cpe:2.3:a:mistune_project:mistune:*:*:*:*:*:*:*:*

History

09 Jul 2026, 19:34

Type Values Removed Values Added
References () https://github.com/lepture/mistune/commit/1bef343ade163fc3bb95572b15be720084cdb993 - () https://github.com/lepture/mistune/commit/1bef343ade163fc3bb95572b15be720084cdb993 - Patch
References () https://github.com/lepture/mistune/releases/tag/v3.3.0 - () https://github.com/lepture/mistune/releases/tag/v3.3.0 - Release Notes
References () https://github.com/lepture/mistune/security/advisories/GHSA-r4rv-85jg-w4mf - () https://github.com/lepture/mistune/security/advisories/GHSA-r4rv-85jg-w4mf - Exploit, Vendor Advisory
First Time Mistune Project
Mistune Project mistune
CPE cpe:2.3:a:mistune_project:mistune:*:*:*:*:*:*:*:*

08 Jul 2026, 18:16

Type Values Removed Values Added
References () https://github.com/lepture/mistune/security/advisories/GHSA-r4rv-85jg-w4mf - () https://github.com/lepture/mistune/security/advisories/GHSA-r4rv-85jg-w4mf -

08 Jul 2026, 17:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-08 17:17

Updated : 2026-07-09 19:34


NVD link : CVE-2026-59924

Mitre link : CVE-2026-59924

CVE.ORG link : CVE-2026-59924


JSON object : View

Products Affected

mistune_project

  • mistune
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')