MEDIUM5.4
PYSEC-2026-1299
Django MarkdownX Cross-Site Scripting (XSS) vulnerability
Details
Cross-Site Scripting (XSS) vulnerability in the Django MarkdownX project, affecting version 4.0.2. An attacker could store a specially crafted JavaScript payload in the upload functionality due to lack of proper sanitisation of JavaScript elements.
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/django-markdownx
Introduced in:
0No fixed version published yet for django-markdownx (pip). Pin to a known-safe version or switch to an alternative.
References
- https://nvd.nist.gov/vuln/detail/CVE-2024-2319[ADVISORY]
- https://github.com/neutronX/django-markdownx[PACKAGE]
- https://www.incibe.es/en/incibe-cert/notices/aviso/cross-site-scripting-vulnerability-django-markdownx[WEB]
- https://pypi.org/project/django-markdownx[PACKAGE]
- https://github.com/advisories/GHSA-fvx8-79hx-x82f[ADVISORY]