MEDIUM6.1
PYSEC-2026-168
Quick fix
PYSEC-2026-168 — mistune: upgrade to the fixed version with the command below.
pip install --upgrade 'mistune>=3.2.1'Details
Mistune is a Python Markdown parser with renderers and plugins. In 3.2.0 and realier, in src/mistune/directives/image.py, the render_figure() function concatenates figclass and figwidth options directly into HTML attributes without escaping. This allows attribute injection and XSS even when HTMLRenderer(escape=True) is used, because these values bypass the inline renderer.
Are you affected?
Enter the version of the package you're using.