DEBIAN-CVE-2026-59924

Source
https://security-tracker.debian.org/tracker/CVE-2026-59924
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-59924.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2026-59924
Upstream
Published
2026-07-08T17:17:28.050Z
Modified
2026-07-09T09:00:32.257246247Z
Severity
  • 5.9 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
[none]
Details

Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, Include.parse() joins and normalizes user-supplied include paths without verifying that the result remains within the intended markdown directory, allowing crafted include paths to access files outside that directory when markdown files are processed using md.read(). This issue is fixed in version 3.3.0.

References

Affected packages

Debian:11 / mistune

Package

Name
mistune
Purl
pkg:deb/debian/mistune?arch=source&distro=bullseye

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

0.*
0.8.4-4
0.8.4-5
2.*
2.0.0~rc1-1~exp1
2.0.0-1
2.0.0-1+really0.8.4-1
2.0.0.0+really2.0.0-1~exp1
2.0.0.0+really2.0.0-1
2.0.2-1
2.0.3-1
2.0.4-1
2.0.4-2
3.*
3.0.2-1
3.0.2-2
3.1.3-1
3.1.4-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-59924.json"

Debian:12 / mistune

Package

Name
mistune
Purl
pkg:deb/debian/mistune?arch=source&distro=bookworm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2.*
2.0.4-1
2.0.4-2
3.*
3.0.2-1
3.0.2-2
3.1.3-1
3.1.4-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-59924.json"

Debian:13 / mistune

Package

Name
mistune
Purl
pkg:deb/debian/mistune?arch=source&distro=trixie

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

3.*
3.1.3-1
3.1.4-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-59924.json"

Debian:14 / mistune

Package

Name
mistune
Purl
pkg:deb/debian/mistune?arch=source&distro=forky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

3.*
3.1.3-1
3.1.4-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-59924.json"