Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-v87v-83h2-53w7 | Mistune Heading ID Attribute has Injection XSS |
Mon, 01 Jun 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 28 May 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mistune Project
Mistune Project mistune |
|
| CPEs | cpe:2.3:a:mistune_project:mistune:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Mistune Project
Mistune Project mistune |
Tue, 26 May 2026 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Lepture
Lepture mistune |
|
| Vendors & Products |
Lepture
Lepture mistune |
Tue, 26 May 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.2.1, HTMLRenderer.heading() builds the opening <hN> tag by string-concatenating the id attribute value directly into the HTML — with no call to escape(), safe_entity(), or any other sanitisation function. A double-quote character " in the id value terminates the attribute, allowing an attacker to inject arbitrary additional attributes (event handlers, src=, href=, etc.) into the heading element. This vulnerability is fixed in 3.2.1. | |
| Title | Mistune Heading ID Attribute Injection XSS | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-06-01T17:09:12.432Z
Reserved: 2026-05-07T21:50:33.546Z
Link: CVE-2026-44897
Updated: 2026-06-01T17:09:07.878Z
Status : Analyzed
Published: 2026-05-26T21:16:39.657
Modified: 2026-06-17T10:51:30.063
Link: CVE-2026-44897
No data.
OpenCVE Enrichment
Updated: 2026-05-26T23:00:17Z
Github GHSA