PYSEC-2017-18

See a problem?
Import Source
https://github.com/pypa/advisory-database/blob/main/vulns/mistune/PYSEC-2017-18.yaml
JSON Data
https://api.test.osv.dev/v1/vulns/PYSEC-2017-18
Aliases
Published
2017-12-29T15:29:00Z
Modified
2023-11-01T04:48:01.180284Z
Summary
[none]
Details

Cross-site scripting (XSS) vulnerability in the _keyify function in mistune.py in Mistune before 0.8.1 allows remote attackers to inject arbitrary web script or HTML by leveraging failure to escape the "key" argument.

References

Affected packages

PyPI / mistune

Package

Affected ranges

Type
GIT
Repo
https://github.com/lepture/mistune
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.8.1

Affected versions

0.*

0.1.0
0.2.0
0.3.0
0.3.1
0.4
0.4.1
0.5
0.5.1
0.6
0.7
0.7.1
0.7.2
0.7.3
0.7.4
0.8