Executive brief
mistune.py in Mistune 0.7.4 allows XSS via an unexpected newline (such as in java\nscript:) or a crafted email address, related to the escape and autolink functions.
Affected products
- PyPI mistune
Junglewise Threat Intelligence
CVE-2017-15612 · Severity: low · CVSS 3 · Published 2017-10-19
Technologies: mistune (PyPI). Vendors: PyPI.
mistune.py in Mistune 0.7.4 allows XSS via an unexpected newline (such as in java\nscript:) or a crafted email address, related to the escape and autolink functions.