Vulnerabilidades en lepture
16 resultadosAnálisis Vexday
Lepture apresenta 16 vulnerabilidades catalogadas, todas publicadas nos últimos 90 dias, indicando um padrão recente de descobertas. Embora nenhuma esteja sob exploração ativa (KEV) ou classificada como crítica, a dominância de falhas XSS (CWE-79) sugere fraquezas em validação de entrada que requerem atenção prioritária na avaliação de risco da aplicação.
CVE-2026-33079HIGHMistune ReDoS in LINK_TITLE_RE allows denial of service with crafted Markdown titlesEPSS 0.5%CVE-2026-59922HIGHMistune plugins/formatting: quadratic-time parsing on long runs of `~~x~~`, `==x==`, and `^^x^^` markers (strikethrough / mark / insert)EPSS 0.4%CVE-2026-59928HIGHMistune block_parser: quadratic-time parsing on long lists of repeated reference-link definitionsEPSS 0.4%CVE-2026-59925HIGHinline_parser: quadratic-time parsing on long runs of `**x**` and `***x***` emphasis pairsEPSS 0.4%CVE-2026-59924MEDIUMMistune: Arbitrary File Read via Include directive path traversalEPSS 0.4%CVE-2026-59927MEDIUMMistune directives/include: mutual `.. include::` recursion crashes the renderer with `RecursionError`, denial of service via two attacker-controlled markdown filesEPSS 0.4%CVE-2026-49851HIGHMistune: Potential DoS via quadratic-time parsing in parse_link_textEPSS 0.3%CVE-2026-59923MEDIUMMistune: XSS via percent-encoded javascript URI bypass in safe_url()EPSS 0.2%CVE-2026-44899MEDIUMMistune Image Directive CSS Injection VulnerabilityEPSS 0.2%CVE-2026-44898MEDIUMMistune TOC Anchor Injection XSSEPSS 0.2%CVE-2026-44897MEDIUMMistune Heading ID Attribute Injection XSSEPSS 0.2%CVE-2026-44708MEDIUMMistune Math Plugin XSS Escape BypassEPSS 0.2%CVE-2026-59929MEDIUMMistune renderers/html.safe_url: HARMFUL_PROTOCOLS list misses legacy and chained schemes that historically chain to `javascript:` executionEPSS 0.2%CVE-2026-44896MEDIUMMistune: XSS via unescaped figclass/figwidth in Figure directiveEPSS 0.2%CVE-2026-59926MEDIUMMistune: XSS via unescaped class option in Admonition directiveEPSS 0.2%CVE-2026-59930MEDIUMMistune toc / TableOfContents directive: heading IDs use predictable `toc_N` numbering with no slugification, allowing collision with attacker-controlled `id="toc_N"` contentEPSS 0.1%