CVE-2017-15612 PUBLISHED

mistune.py in Mistune 0.7.4 allows XSS via an unexpected newline (such as in java\nscript:) or a crafted email address, related to the escape and autolink functions.

EPSS 0.22% · 44.8th percentile

Risk Scores

EPSS Score
0.22%
44.8th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSmistune0, 0.6-2, 0.7.1-1

Timeline

References

Open in Interactive Console →