CVE-2017-16876 PUBLISHED

Cross-site scripting (XSS) vulnerability in the _keyify function in mistune.py in Mistune before 0.8.1 allows remote attackers to inject arbitrary web script or HTML by leveraging failure to escape the "key" argument.

EPSS 0.58% · 68.7th percentile

Risk Scores

EPSS Score
0.58%
68.7th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSmistune0, 0.6-2, 0.7.1-1

Timeline

References

Open in Interactive Console →