{"id":"GHSA-8c25-4j27-2rv3","summary":"Mistune: XSS via percent-encoded javascript URI bypass in safe_url()","details":"### Summary\nAn XSS vulnerability in Mistune allows bypassing of safe_url() protections via percent-encoded javascript URIs.\n\n\n### Details\nThe vulnerability exists in HTMLRenderer.safe_url() in Mistune.\n\nThe function is intended to block harmful URL schemes such as \"javascript:\" by checking the prefix of the provided URL:\n\n    _url = url.lower()\n    if _url.startswith(self.HARMFUL_PROTOCOLS):\n        return \"#harmful-link\"\n\nHowever, the input URL is not URL-decoded before this check. Because of this, an attacker can use percent-encoding to bypass the filter. For example:\n\n    javascript%3Aalert(1)\n\nSince \"%3A\" is not decoded to \":\", the check does not detect the \"javascript:\" scheme.\n\nWhen rendered in a browser, the URL is decoded, resulting in execution of arbitrary JavaScript upon user interaction.\n\nThis effectively bypasses Mistune's built-in safe_url() protection mechanism.\n\n\n\n### PoC\n1. Install vulnerable version:\n\n    pip install mistune==3.2.0\n\n2. Run the following code:\n\n    import mistune\n\n    markdown = mistune.create_markdown()\n    html = markdown(\"[j](javascript%3Aalert(1))\")\n\n    print(html)\n\n3. Output:\n\n    \u003cp\u003e\u003ca href=\"javascript%3Aalert(1)\"\u003ej\u003c/a\u003e\u003c/p\u003e\n\n4. Open the rendered HTML in a browser and click the link.\n\n5. The browser decodes \"%3A\" into \":\" and executes:\n\n    javascript:alert(1)\n\n\n### Impact\nThis is a cross-site scripting (XSS) vulnerability.\n\nAn attacker can craft a malicious Markdown link that executes JavaScript in the victim's browser when clicked.\n\nImpact includes:\n- Session hijacking (e.g., cookie theft)\n- Execution of arbitrary JavaScript in the victim's context\n- Potential account takeover depending on the application\n\nThis affects any application that renders user-controlled Markdown using Mistune without additional URL sanitization.","aliases":["CVE-2026-59923","PYSEC-2026-2211"],"modified":"2026-07-20T21:46:40.379029796Z","published":"2026-07-20T21:32:49Z","database_specific":{"cwe_ids":["CWE-79"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-07-20T21:32:49Z","nvd_published_at":"2026-07-08T17:17:27Z"},"references":[{"type":"WEB","url":"https://github.com/lepture/mistune/security/advisories/GHSA-8c25-4j27-2rv3"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-59923"},{"type":"WEB","url":"https://github.com/lepture/mistune/commit/c7101fcbb6e8790e8e39157c5ca2238fc6dd6cbc"},{"type":"PACKAGE","url":"https://github.com/lepture/mistune"},{"type":"WEB","url":"https://github.com/lepture/mistune/releases/tag/v3.3.0"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/mistune/PYSEC-2026-2211.yaml"}],"affected":[{"package":{"name":"mistune","ecosystem":"PyPI","purl":"pkg:pypi/mistune"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.3.0"}]}],"versions":["0.1.0","0.2.0","0.3.0","0.3.1","0.4","0.4.1","0.5","0.5.1","0.6","0.7","0.7.1","0.7.2","0.7.3","0.7.4","0.8","0.8.1","0.8.2","0.8.3","0.8.4","2.0.0","2.0.0a1","2.0.0a2","2.0.0a3","2.0.0a4","2.0.0a5","2.0.0a6","2.0.0rc1","2.0.1","2.0.2","2.0.3","2.0.4","2.0.5","2.1.0","3.0.0","3.0.0a1","3.0.0a2","3.0.0a3","3.0.0rc1","3.0.0rc2","3.0.0rc3","3.0.0rc4","3.0.0rc5","3.0.1","3.0.2","3.1.0","3.1.1","3.1.2","3.1.3","3.1.4","3.2.0","3.2.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-8c25-4j27-2rv3/GHSA-8c25-4j27-2rv3.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}