SCA: security update for pymdown-extensions (GHSA-jh85-wwv9-24hv)

high Tenable Self-Hosted Container Security Plugin ID 416385

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- PyMdown Extensions is a set of extensions for the `Python-Markdown` markdown project. In affected versions
an arbitrary file read is possible when using include file syntax. By using the syntax
`--8<--"/etc/passwd"` or `--8<--"/proc/self/environ"` the content of these files will be rendered in the
generated documentation. Additionally, a path relative to a specified, allowed base path can also be used
to render the content of a file outside the specified base paths: `--8<-- "../../../../etc/passwd"`.
Within the Snippets extension, there exists a `base_path` option but the implementation is vulnerable to
Directory Traversal. The vulnerable section exists in `get_snippet_path(self, path)` lines 155 to 174 in
snippets.py. Any readable file on the host where the plugin is executing may have its content exposed.
This can impact any use of Snippets that exposes the use of Snippets to external users. It is never
recommended to use Snippets to process user-facing, dynamic content. It is designed to process known
content on the backend under the control of the host, but if someone were to accidentally enable it for
user-facing content, undesired information could be exposed. This issue has been addressed in version
10.0. Users are advised to upgrade. Users unable to upgrade may restrict relative paths by filtering
input. (CVE-2023-32309)

See Also

https://github.com/advisories/GHSA-jh85-wwv9-24hv

Plugin Details

Severity: High

ID: 416385

Version: Revision 1.7

Type: Local

Family: SCA Checks

Published: 1/23/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.51

Vendor

Vendor Severity: High

CVSS v2

Risk Factor: High

Base Score: 7.8

Temporal Score: 6.1

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:N/A:N

CVSS Score Source: CVE-2023-32309

CVSS v3

Risk Factor: High

Base Score: 7.5

Temporal Score: 6.7

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 5/15/2023

Vulnerability Publication Date: 5/15/2023

Reference Information

CVE: CVE-2023-32309

cwe: CWE-22