Vulnerability Description
Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, the toc plugin and TableOfContents directive generate heading IDs as predictable toc_N values without slugifying the heading text, allowing attacker-controlled id="toc_N" content to collide with generated anchors and redirect same-page navigation, CSS selectors, or JavaScript handlers. This issue is fixed in version 3.3.0.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mistune Project | Mistune | < 3.3.0 |
Related Weaknesses (CWE)
References
- https://github.com/lepture/mistune/commit/c4093c4742ed0d10d9332fb8edb455869b7b58Patch
- https://github.com/lepture/mistune/releases/tag/v3.3.0Release Notes
- https://github.com/lepture/mistune/security/advisories/GHSA-2hm2-hc3v-44h9ExploitThird Party Advisory
- https://github.com/lepture/mistune/security/advisories/GHSA-2hm2-hc3v-44h9ExploitThird Party Advisory
FAQ
What is CVE-2026-59930?
CVE-2026-59930 is a vulnerability with a CVSS score of 4.3 (MEDIUM). Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, the toc plugin and TableOfContents directive generate heading IDs as predictable toc_N values without slugifying the hea...
How severe is CVE-2026-59930?
CVE-2026-59930 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-59930?
Check the references section above for vendor advisories and patch information. Affected products include: Mistune Project Mistune.