CVE-2026-59923: Mistune: XSS via percent-encoded javascript URI bypass in safe_url()
An XSS vulnerability in Mistune allows bypassing of safe_url() protections via percent-encoded javascript URIs.
References
- github.com/advisories/GHSA-8c25-4j27-2rv3
- github.com/lepture/mistune/commit/c7101fcbb6e8790e8e39157c5ca2238fc6dd6cbc
- github.com/lepture/mistune/releases/tag/v3.3.0
- github.com/lepture/mistune/security/advisories/GHSA-8c25-4j27-2rv3
- github.com/pypa/advisory-database/tree/main/vulns/mistune/PYSEC-2026-2211.yaml
- nvd.nist.gov/vuln/detail/CVE-2026-59923
Code Behaviors & Features
Detect and mitigate CVE-2026-59923 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →