Debian Package Tracker
Register | Log in
Subscribe

pymdown-extensions

Extension pack for Python Markdown

Choose email to subscribe with

general
  • source: pymdown-extensions (main)
  • version: 11.0.1-1
  • maintainer: Debian Python Team (DMD)
  • uploaders: Alexandre Detiste [DMD]
  • arch: all
  • std-ver: 4.7.4
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • oldstable: 9.5-2
  • stable: 10.13-1+deb13u1
  • testing: 11.0.1-1
  • unstable: 11.0.1-1
versioned links
  • 9.5-2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 10.13-1+deb13u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 11.0.1-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • python3-pymdownx
action needed
Debci reports failed tests high
  • unstable: fail (log)
    The tests ran in 0:01:37
    Last run: 2026-07-12T18:35:07.000Z
    Previous status: unknown

  • testing: pass (log)
    The tests ran in 0:01:17
    Last run: 2026-07-12T16:20:47.000Z
    Previous status: unknown

  • stable: pass (log)
    The tests ran in 0:00:49
    Last run: 2026-07-17T18:02:55.000Z
    Previous status: unknown

Created: 2026-07-12 Last update: 2026-07-29 09:01
1 security issue in trixie high

There is 1 open security issue in trixie.

1 important issue:
  • CVE-2026-46338: PyMdown Extensions is a set of extensions for the Python-Markdown markdown project. From 10.0.1 until 10.21.3, pymdownx.snippets uses a string-prefix containment check in SnippetPreprocessor.get_snippet_path() in pymdownx/snippets.py when `restrict_base_path: True`, allowing markdown snippet directives to read files from sibling paths that share the same base_path prefix, such as docs and docs_internal. This is a regression of CVE-2023-32309. This issue is fixed in version 10.21.3.
Created: 2026-07-18 Last update: 2026-07-21 17:00
2 security issues in bookworm high

There are 2 open security issues in bookworm.

1 important issue:
  • CVE-2026-46338: PyMdown Extensions is a set of extensions for the Python-Markdown markdown project. From 10.0.1 until 10.21.3, pymdownx.snippets uses a string-prefix containment check in SnippetPreprocessor.get_snippet_path() in pymdownx/snippets.py when `restrict_base_path: True`, allowing markdown snippet directives to read files from sibling paths that share the same base_path prefix, such as docs and docs_internal. This is a regression of CVE-2023-32309. This issue is fixed in version 10.21.3.
1 issue left for the package maintainer to handle:
  • CVE-2023-32309: (postponed; to be fixed through a stable update) PyMdown Extensions is a set of extensions for the `Python-Markdown` markdown project. In affected versions an arbitrary file read is possible when using include file syntax. By using the syntax `--8<--"/etc/passwd"` or `--8<--"/proc/self/environ"` the content of these files will be rendered in the generated documentation. Additionally, a path relative to a specified, allowed base path can also be used to render the content of a file outside the specified base paths: `--8<-- "../../../../etc/passwd"`. Within the Snippets extension, there exists a `base_path` option but the implementation is vulnerable to Directory Traversal. The vulnerable section exists in `get_snippet_path(self, path)` lines 155 to 174 in snippets.py. Any readable file on the host where the plugin is executing may have its content exposed. This can impact any use of Snippets that exposes the use of Snippets to external users. It is never recommended to use Snippets to process user-facing, dynamic content. It is designed to process known content on the backend under the control of the host, but if someone were to accidentally enable it for user-facing content, undesired information could be exposed. This issue has been addressed in version 10.0. Users are advised to upgrade. Users unable to upgrade may restrict relative paths by filtering input.

You can find information about how to handle this issue in the security team's documentation.

Created: 2026-07-18 Last update: 2026-07-21 17:00
lintian reports 3 warnings normal
Lintian reports 3 warnings about this package. You should make the package lintian clean getting rid of them.
Created: 2026-01-01 Last update: 2026-01-01 07:00
news
[rss feed]
  • [2026-07-15] pymdown-extensions 11.0.1-1 MIGRATED to testing (Debian testing watch)
  • [2026-07-12] Accepted pymdown-extensions 11.0.1-1 (source) into unstable (Alexandre Detiste)
  • [2026-07-04] Accepted pymdown-extensions 10.13-1+deb13u1 (source) into proposed-updates (Debian FTP Masters) (signed by: Adrian Bunk)
  • [2026-01-13] pymdown-extensions 10.19.1-3 MIGRATED to testing (Debian testing watch)
  • [2026-01-02] Accepted pymdown-extensions 10.19.1-3 (source) into unstable (Colin Watson)
  • [2025-12-31] Accepted pymdown-extensions 10.19.1-1 (source) into unstable (Colin Watson)
  • [2025-12-30] Accepted pymdown-extensions 10.13-4 (source) into unstable (Dmitry Shachnev)
  • [2025-08-29] pymdown-extensions 10.13-3 MIGRATED to testing (Debian testing watch)
  • [2025-08-27] Accepted pymdown-extensions 10.13-3 (source) into unstable (Dmitry Shachnev)
  • [2025-08-26] Accepted pymdown-extensions 10.13-2 (source) into unstable (Dmitry Shachnev)
  • [2024-12-26] pymdown-extensions 10.13-1 MIGRATED to testing (Debian testing watch)
  • [2024-12-23] Accepted pymdown-extensions 10.13-1 (source) into unstable (Alexandre Detiste)
  • [2024-10-18] pymdown-extensions 10.11.2-1 MIGRATED to testing (Debian testing watch)
  • [2024-10-16] Accepted pymdown-extensions 10.11.2-1 (source) into unstable (Alexandre Detiste)
  • [2024-08-08] pymdown-extensions 10.9-1 MIGRATED to testing (Debian testing watch)
  • [2024-08-05] Accepted pymdown-extensions 10.9-1 (source) into unstable (Boyuan Yang)
  • [2024-05-03] pymdown-extensions 10.8.1-1 MIGRATED to testing (Debian testing watch)
  • [2024-04-30] Accepted pymdown-extensions 10.8.1-1 (source) into unstable (Boyuan Yang)
  • [2024-03-26] pymdown-extensions 9.5-5 MIGRATED to testing (Debian testing watch)
  • [2024-03-23] Accepted pymdown-extensions 9.5-5 (source) into unstable (Dmitry Shachnev)
  • [2024-03-07] pymdown-extensions 9.5-4 MIGRATED to testing (Debian testing watch)
  • [2024-03-01] Accepted pymdown-extensions 9.5-4 (source) into unstable (Sandro Tosi)
  • [2024-03-01] Accepted pymdown-extensions 9.5-3 (source) into unstable (Sandro Tosi)
  • [2022-07-16] pymdown-extensions 9.5-2 MIGRATED to testing (Debian testing watch)
  • [2022-07-01] Accepted pymdown-extensions 9.5-2 (source) into unstable (Sandro Tosi)
  • [2022-07-01] Accepted pymdown-extensions 9.5-1 (source all) into unstable, unstable (Debian FTP Masters) (signed by: Sandro Tosi)
bugs [bug history graph]
  • all: 0
links
  • homepage
  • lintian (0, 3)
  • buildd: logs, reproducibility
  • popcon
  • browse source code
  • other distros
  • security tracker
  • debci
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 11.0.1-1

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing