Mistune: XSS via percent-encoded javascript URI bypass in safe_url()
위협 신호 · CVSS · EPSS · KEV
이론적 심각도 점수
30일 내 악용 확률 예측
실측 악용 기록 없음
계획된 패치 주기 내 조치(60일 이내)
CVSS 벡터 · 메트릭
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N상세 설명
Summary
An XSS vulnerability in Mistune allows bypassing of safe_url() protections via percent-encoded javascript URIs.
Details
The vulnerability exists in HTMLRenderer.safe_url() in Mistune.
The function is intended to block harmful URL schemes such as "javascript:" by checking the prefix of the provided URL:
1_url = url.lower() 2if _url.startswith(self.HARMFUL_PROTOCOLS): 3 return "#harmful-link"However, the input URL is not URL-decoded before this check. Because of this, an attacker can use percent-encoding to bypass the filter. For example:
1javascript%3Aalert(1)Since "%3A" is not decoded to ":", the check does not detect the "javascript:" scheme.
When rendered in a browser, the URL is decoded, resulting in execution of arbitrary JavaScript upon user interaction.
This effectively bypasses Mistune's built-in safe_url() protection mechanism.
PoC
-
Install vulnerable version:
pip install mistune==3.2.0
-
Run the following code:
import mistune
markdown = mistune.create_markdown()
html = markdown("j")print(html)
-
Output:
<p><a href="javascript%3Aalert(1)">j</a></p> -
Open the rendered HTML in a browser and click the link.
-
The browser decodes "%3A" into ":" and executes:
javascript:alert(1)
Impact
This is a cross-site scripting (XSS) vulnerability.
An attacker can craft a malicious Markdown link that executes JavaScript in the victim's browser when clicked.
Impact includes:
- Session hijacking (e.g., cookie theft)
- Execution of arbitrary JavaScript in the victim's context
- Potential account takeover depending on the application
This affects any application that renders user-controlled Markdown using Mistune without additional URL sanitization.
AI 심층 분석
공격 시나리오 · 재현 가능한 PoC 페이로드 · 즉시 적용 가능한 차단 패치를 한 번에 받아 보세요. 보안 운영팀이 그대로 점검·티켓팅에 쓸 수 있는 형태로 정리해 드립니다.
참고 자료 6
링크 내용 불러오는 중…