{"id":"CVE-2026-46338","summary":"PyMdown Extensions: Regression in pymdownx.snippets reintroduces sibling-prefix path traversal bypass despite restrict_base_path","details":"PyMdown Extensions is a set of extensions for the Python-Markdown markdown project. From 10.0.1 until 10.21.3, pymdownx.snippets uses a string-prefix containment check in SnippetPreprocessor.get_snippet_path() in pymdownx/snippets.py when `restrict_base_path: True`, allowing markdown snippet directives to read files from sibling paths that share the same base_path prefix, such as docs and docs_internal. This is a regression of CVE-2023-32309. This issue is fixed in version 10.21.3.","aliases":["GHSA-62q4-447f-wv8h","PYSEC-2026-2999"],"modified":"2026-08-01T03:46:33.437317339Z","published":"2026-07-16T18:24:18.155Z","related":["CGA-6h3p-9ffx-7xv2"],"database_specific":{"cwe_ids":["CWE-22"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/46xxx/CVE-2026-46338.json","cna_assigner":"GitHub_M"},"references":[{"type":"WEB","url":"https://github.com/facelessuser/pymdown-extensions/releases/tag/10.21.3"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/46xxx/CVE-2026-46338.json"},{"type":"ADVISORY","url":"https://github.com/facelessuser/pymdown-extensions/security/advisories/GHSA-62q4-447f-wv8h"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-46338"},{"type":"FIX","url":"https://github.com/facelessuser/pymdown-extensions/commit/63b7835776d703d6c339cf2110d9888f676efc0c"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/facelessuser/pymdown-extensions","events":[{"introduced":"7c13bda5b7793b172efd1abb6712e156a83fe07d"},{"fixed":"42628414c6591b1a1ce211157090783e3b2242d6"},{"fixed":"63b7835776d703d6c339cf2110d9888f676efc0c"}],"database_specific":{"extracted_events":[{"introduced":"10.0.1"},{"fixed":"10.21.3"}],"source":["CPE_RANGE","REFERENCES"],"cpe":"cpe:2.3:a:facelessuser:pymdown_extensions:*:*:*:*:*:*:*:*"}}],"versions":["10.21.2","10.21","10.21.1","10.20","10.19.1","10.19","10.18","10.17.2","10.17.1","10.17","10.16.1","10.16","10.15","10.14.3","10.14.2","10.14.1","10.14","10.13","10.12","10.11.2","10.11.1","10.11","10.10.2","10.10.1","10.10","10.9","10.8.1","10.8","10.7.1","10.7","10.6","10.5","10.4","10.3.1","10.3","10.2.1","10.2","10.1.0","10.0.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-46338.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"}]}