MEDIUMPyPI

PyMdown Extensions: Path traversal in the b64 extension lets <img src> read files outside base_path

PyMdown Extensions: Path traversal in the b64 extension lets <img src> read files outside base_path

CVE-2026-61632Published 1 week agoUpdated 1 day agoSource: OSV

Affected packages

  • pymdown-extensionsbefore 11.0.0

Exploit signal

Known exploited (CISA KEV)
No
EPSS score
EPSS percentile

EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs.

PyMdown Extensions: Path traversal in the b64 extension lets <img src> read files outside base_path | HackTribune