Vulnerabilidades en lepture
17 resultadosAnálisis Vexday
Lepture apresenta 16 vulnerabilidades catalogadas, todas publicadas nos últimos 90 dias, indicando um padrão recente de descobertas. Embora nenhuma esteja sob exploração ativa (KEV) ou classificada como crítica, a dominância de falhas XSS (CWE-79) sugere fraquezas em validação de entrada que requerem atenção prioritária na avaliação de risco da aplicação.
CVE-2026-33079HIGHMistune ReDoS in LINK_TITLE_RE allows denial of service with crafted Markdown titlesEPSS 0.7%CVE-2026-59928HIGHMistune block_parser: quadratic-time parsing on long lists of repeated reference-link definitionsEPSS 0.7%CVE-2026-59922HIGHMistune plugins/formatting: quadratic-time parsing on long runs of `~~x~~`, `==x==`, and `^^x^^` markers (strikethrough / mark / insert)EPSS 0.6%CVE-2026-59925HIGHinline_parser: quadratic-time parsing on long runs of `**x**` and `***x***` emphasis pairsEPSS 0.6%CVE-2026-49851HIGHMistune: Potential DoS via quadratic-time parsing in parse_link_textEPSS 0.6%CVE-2026-59927MEDIUMMistune directives/include: mutual `.. include::` recursion crashes the renderer with `RecursionError`, denial of service via two attacker-controlled markdown filesEPSS 0.5%CVE-2026-76098HIGHMistune has Denial of Service — RecursionError via Excessive Emphasis Markers in MarkdownEPSS 0.5%CVE-2026-59924MEDIUMMistune: Arbitrary File Read via Include directive path traversalEPSS 0.5%CVE-2026-59923MEDIUMMistune: XSS via percent-encoded javascript URI bypass in safe_url()EPSS 0.3%CVE-2026-59929MEDIUMMistune renderers/html.safe_url: HARMFUL_PROTOCOLS list misses legacy and chained schemes that historically chain to `javascript:` executionEPSS 0.3%CVE-2026-59926MEDIUMMistune: XSS via unescaped class option in Admonition directiveEPSS 0.3%CVE-2026-44899MEDIUMMistune Image Directive CSS Injection VulnerabilityEPSS 0.3%CVE-2026-44897MEDIUMMistune Heading ID Attribute Injection XSSEPSS 0.3%CVE-2026-44896MEDIUMMistune: XSS via unescaped figclass/figwidth in Figure directiveEPSS 0.3%CVE-2026-44898MEDIUMMistune TOC Anchor Injection XSSEPSS 0.3%CVE-2026-44708MEDIUMMistune Math Plugin XSS Escape BypassEPSS 0.3%CVE-2026-59930MEDIUMMistune toc / TableOfContents directive: heading IDs use predictable `toc_N` numbering with no slugification, allowing collision with attacker-controlled `id="toc_N"` contentEPSS 0.2%