{"id":"CVE-2026-44896","aliases":["GHSA-58cw-g322-p94v","PYSEC-2026-168"],"url":"https://o3.security/vulnerability/CVE-2026-44896","summary":"Mistune: XSS via unescaped figclass/figwidth in Figure directive","details":"Mistune is a Python Markdown parser with renderers and plugins. In 3.2.0 and earlier, in src/mistune/directives/image.py, the render_figure() function concatenates figclass and figwidth options directly into HTML attributes without escaping. This allows attribute injection and XSS even when HTMLRenderer(escape=True) is used, because these values bypass the inline renderer. Version 3.2.1 contains a patch.","published":"2026-05-26T20:33:38.696Z","modified":"2026-08-07T11:49:54.315197751Z","cvss":null,"epss":{"score":0.00198,"percentile":0.09799,"asOf":"2026-08-08"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"mistune","fixedVersion":"3.2.1"}],"fix":{"url":"https://github.com/lepture/mistune/commit/a3cb6e5655308797e8be021d6c7b5bab13cbace2","label":"lepture/mistune@a3cb6e5"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/44xxx/CVE-2026-44896.json"},{"type":"ADVISORY","url":"https://github.com/lepture/mistune/security/advisories/GHSA-58cw-g322-p94v"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-44896"},{"type":"FIX","url":"https://github.com/lepture/mistune/commit/a3cb6e5655308797e8be021d6c7b5bab13cbace2"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T11:49:54.315197751Z"}}