CVE-2026-59930
MEDIUMMistune < 3.3.0 TOC Plugin - Predictable Heading ID Collision
Title source: manualDescription
Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, the toc plugin and TableOfContents directive generate heading IDs as predictable toc_N values without slugifying the heading text, allowing attacker-controlled id="toc_N" content to collide with generated anchors and redirect same-page navigation, CSS selectors, or JavaScript handlers. This issue is fixed in version 3.3.0.
References (3)
Core 3
Core References
X_Refsource_Confirm x_refsource_confirm
https://github.com/lepture/mistune/security/advisories/GHSA-2hm2-hc3v-44h9
X_Refsource_Misc x_refsource_misc
https://github.com/lepture/mistune/commit/c4093c4742ed0d10d9332fb8edb455869b7b581b
X_Refsource_Misc x_refsource_misc
https://github.com/lepture/mistune/releases/tag/v3.3.0
Scores
CVSS v3
4.3
EPSS
0.0014
EPSS Percentile
3.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-1284
CWE-345
Status
published
Products (3)
lepture/mistune
< 3.3.0
mistune_project/mistune
< 3.3.0
pypi/mistune
0 - 3.3.0PyPI
Published
Jul 08, 2026
Tracked Since
Jul 08, 2026