{"id":"GHSA-98gj-wwxm-cj3h","summary":"mistune Cross-site scripting (XSS) vulnerability","details":"Cross-site scripting (XSS) vulnerability in the _keyify function in mistune.py in Mistune before 0.8.1 allows remote attackers to inject arbitrary web script or HTML by leveraging failure to escape the \"key\" argument.","aliases":["CVE-2017-16876","PYSEC-2017-18"],"modified":"2024-09-24T21:34:24.653510Z","published":"2019-01-04T17:47:50Z","database_specific":{"cwe_ids":["CWE-79"],"github_reviewed_at":"2020-06-16T21:27:52Z","github_reviewed":true,"nvd_published_at":null,"severity":"MODERATE"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2017-16876"},{"type":"WEB","url":"https://github.com/lepture/mistune/commit/5f06d724bc05580e7f203db2d4a4905fc1127f98"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1524596"},{"type":"PACKAGE","url":"https://github.com/lepture/mistune"},{"type":"WEB","url":"https://github.com/lepture/mistune/blob/master/CHANGES.rst"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/mistune/PYSEC-2017-18.yaml"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NUR3GMHQBMA3UC4PFMCK6GCLOQC4LQQC"}],"affected":[{"package":{"name":"mistune","ecosystem":"PyPI","purl":"pkg:pypi/mistune"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.8.1"}]}],"versions":["0.1.0","0.2.0","0.3.0","0.3.1","0.4","0.4.1","0.5","0.5.1","0.6","0.7","0.7.1","0.7.2","0.7.3","0.7.4","0.8"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/01/GHSA-98gj-wwxm-cj3h/GHSA-98gj-wwxm-cj3h.json"}}],"schema_version":"1.7.3","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N"}]}