VDB
Sign up
MEDIUM5.4

PYSEC-2026-1299

Django MarkdownX Cross-Site Scripting (XSS) vulnerability

Details

Cross-Site Scripting (XSS) vulnerability in the Django MarkdownX project, affecting version 4.0.2. An attacker could store a specially crafted JavaScript payload in the upload functionality due to lack of proper sanitisation of JavaScript elements.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/django-markdownx
Introduced in: 0

No fixed version published yet for django-markdownx (pip). Pin to a known-safe version or switch to an alternative.

References