CVE-2026-59930

Summary

Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, the toc plugin and TableOfContents directive generate heading IDs as predictable toc_N values without slugifying the heading text, allowing attacker-controlled id="toc_N" content to collide with generated anchors and redirect same-page navigation, CSS selectors, or JavaScript handlers. This issue is fixed in version 3.3.0.

Affected Software

VendorProductVersion RangeStatus
lepturemistune< 3.3.0affected

Weaknesses

  • CWE-345: CWE-345: Insufficient Verification of Data Authenticity
  • CWE-1284: CWE-1284: Improper Validation of Specified Quantity in Input

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: poc
    • Automatable: no
    • Technical Impact: partial

Additional References

References