mistune.py in Mistune 0.7.4 allows XSS via an unexpected newline (such as in java\nscript:) or a crafted email address, related to the escape and autolink functions (CVE-2017-15612).
A cross-site-scripting vulnerability was found in python-mistune (CVE-2017-16876).