Where
-Infinity
0

Vendor Risk Score

See how mistune project compares to other vendors in security performance

View Risk Score →

Mistune MistuneMistune directives/include: mutual `.. include::` recursion crashes the renderer with `RecursionError`, denial of service via two attacker-controlled markdown files

Risk 27
Severity
5.3
First published (updated )

Mistune MistuneMistune block_parser: quadratic-time parsing on long lists of repeated reference-link definitions

Risk 43
Severity
7.5
First published (updated )

Mistune MistuneMistune: Arbitrary File Read via Include directive path traversal

Risk 35
Severity
5.9
First published (updated )

Mistune MistuneMistune renderers/html.safe_url: HARMFUL_PROTOCOLS list misses legacy and chained schemes that historically chain to `javascript:` execution

Risk 38
Severity
6.1
First published (updated )

Mistune Mistuneinline_parser: quadratic-time parsing on long runs of `**x**` and `***x***` emphasis pairs

Risk 43
Severity
7.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Mistune MistuneMistune: XSS via unescaped class option in Admonition directive

Risk 38
Severity
5.3
First published (updated )

Mistune MistuneMistune: XSS via percent-encoded javascript URI bypass in safe_url()

Risk 38
Severity
6.1
First published (updated )

Mistune MistuneMistune toc / TableOfContents directive: heading IDs use predictable `toc_N` numbering with no slugification, allowing collision with attacker-controlled `id="toc_N"` content

Risk 22
Severity
4.3
First published (updated )

Mistune MistuneMistune plugins/formatting: quadratic-time parsing on long runs of `~~x~~`, `==x==`, and `^^x^^` markers (strikethrough / mark / insert)

Risk 43
Severity
7.5
First published (updated )

pip/mistuneMistune Image Directive CSS Injection Vulnerability

Risk 38
Severity
6.1
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

pip/mistuneMistune TOC Anchor Injection XSS

Risk 38
Severity
6.1
First published (updated )

pip/mistuneMistune Heading ID Attribute Injection XSS

Risk 38
Severity
6.1
First published (updated )

pip/mistuneMistune: XSS via unescaped figclass/figwidth in Figure directive

Risk 38
Severity
5.3
First published (updated )

pip/mistuneMistune Math Plugin XSS Escape Bypass

Risk 38
Severity
6.1
First published (updated )

IBM Watson Studio on Cloud Pak for DataIn mistune through 2.0.2, support of inline markup is implemented by using regular expressions that …

Risk 68
Severity
8.6
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

pip/mistuneXSS

Risk 39
Severity
6.1
First published (updated )

pip/mistuneXSS

Risk 38
Severity
6.1
First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203