VDB
Sign up
—

PYSEC-2023-23

Quick fix

PYSEC-2023-23 — markdown-it-py: upgrade to the fixed version with the command below.

pip install --upgrade 'markdown-it-py>=53ca3e9c2b9e9b295f6abf7f4ad2730a9b70f68c'

Details

Denial of service could be caused to the command line interface of markdown-it-py, before v2.2.0, if an attacker was allowed to use invalid UTF-8 characters as input.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/markdown-it-py
Introduced in: 0Fixed in: 53ca3e9c2b9e9b295f6abf7f4ad2730a9b70f68c
Fixpip install --upgrade 'markdown-it-py>=53ca3e9c2b9e9b295f6abf7f4ad2730a9b70f68c'

References