🛡️ CVE-2026-59930 — mistune
Description
Introduction
` — with a numeric suffix appended only when slug collisions occur. mistune's default punts the slugification entirely and produces purely positional IDs that an attacker can predict in O(1). The downstream impacts: - Same-page links with `[click](#toc_1)` go to whichever element with `id="toc_1"` appears first in tree order. If the attacker can land any HTML element with `id="toc_1"` before the real heading (via inline_html with `escape=False`, via the include-directive HTML branch, via attacker-supplied content earlier in the document), navigation is hijacked. - CSS rules targeting `#toc_1` apply to the wrong element. - JavaScript bound to `document.getElementById('toc_1')` operates on the wrong element. - The TOC's own `` link in the rendered TOC list points to whichever element wins the duplicate-ID race. ## Exploit Chain 1. Application uses mistune with `add_toc_hook(md)` or `TableOfContents` directive enabled (the documented setup for sites with TOC support). 2. Application renders an attacker-supplied document, or splices attacker content into a trusted document. With `escape=False` (or via the include-directive `.html` branch covered by my prior advisory), the attacker can place `...` anywhere in the document. 3. mistune assigns `id="toc_1"` to the first heading. Now there are two elements with `id="toc_1"` in the page. 4. The rendered TOC contains `First heading`. Clicking it navigates to whichever element with `id="toc_1"` appears first in tree order. If the attacker placed their `` BEFORE the heading, navigation is hijacked. 5. Same-page CSS / JS / aria-described references to `#toc_1` similarly redirect. ## Security Impact **Severity:** sec-low. Not a direct XSS or RCE; the issue is identifier confusion that enables UI-redirection / navigation-hijack attacks. The realistic attacker capability is "make an internal anchor link go to attacker content instead of the real heading", or "make a CSS selector apply to attacker content", or "break aria/screen-reader associations". **Attacker capability:** with the ability to plant any HTML element with `id="toc_N"` in the document, hijack `` navigation and any CSS/JS targeting that ID. With `escape=False`, this is straightforward. With `escape=True`, the attacker needs another vector to land a raw `id` attribute (one of the include-directive branches, a sibling tooling pipeline that lets HTML through, etc.). **Preconditions:** applicatiHow this vulnerability can be exploited
This issue can be reached over the network, attack complexity is low, an attacker needs no privileges on the target. A user must be tricked into taking some action. The scope is unchanged, so the impact stays within the vulnerable component. Rated impact: confidentiality none, integrity low, availability none.
Affected software
CVE-2026-59930 is recorded against 1 package.
- mistune (fixed in 3.3.0)
Timeline and source
Published on 20 July 2026. A public exploit is known to exist, which raises the urgency of patching considerably. A vendor advisory or fix has been published. Record sourced from OSV.
References
github.com (Web)
nvd.nist.gov (Advisory)
github.com (Web)
github.com (Package)
github.com (Web)
github.com (Web)
Details
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Affected Packages
| Software | From version | Fixed in |
|---|---|---|
| mistune | — | 3.3.0 |
References
Similar Threats
- High CVE-2026-59922
- Medium CVE-2026-59923
- Medium CVE-2026-59924
- Medium CVE-2026-59926
- High CVE-2026-59925
More CVE 2026 advisories
Browse all of CVE 2026 in the advisory index.
Exploit Protection
Are you running mistune?
CVE-2026-59930 carries CVSS 4.3 Medium rating and a public exploit already exists. BotEraser checks your installation against this and other known CVE records, and blocks IPs associated with exploit activity.
Check My Site For CVE-2026-59930 →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.