CVE-2026-59924

Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, Include.parse() joins and normalizes user-supplied include paths without verifying that the result remains within the intended markdown directory, allowing crafted include paths to access files outside that directory when markdown files are processed using md.read(). This issue is fixed in version 3.3.0.
Configurations

Configuration 1 (hide)

cpe:2.3:a:mistune_project:mistune:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-07-08 17:17

Updated : 2026-07-09 19:34


NVD link : CVE-2026-59924

Mitre link : CVE-2026-59924

CVE.ORG link : CVE-2026-59924


JSON object : View

Products Affected

mistune_project

  • mistune
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')