Junglewise Threat Intelligence

CVE-2017-15612: PYSEC-2017-80 - mistune.py in Mistune 0.7.4 allows XSS via an unexpected newline (such as in java\nscript:) or a crafted email address, related to the escap

CVE-2017-15612 · Severity: low · CVSS 3 · Published 2017-10-19

Technologies: mistune (PyPI). Vendors: PyPI.

Executive brief

mistune.py in Mistune 0.7.4 allows XSS via an unexpected newline (such as in java\nscript:) or a crafted email address, related to the escape and autolink functions.

Affected products

  • PyPI mistune

Related threats