From a309ef1551159a8ec99b20c14697986723eb3764 Mon Sep 17 00:00:00 2001 From: rmz-oz <262968088+rmz-oz@users.noreply.github.com> Date: Thu, 24 Sep 2026 13:22:13 +0300 Subject: [PATCH 1/2] Fix zero-padded colon entities passing _safe_href check Numeric character references may carry leading zeros, so `javascript:alert(1)` and `javascript:alert(1)` decode to javascript: URLs, but the protocol separator patterns only matched `:` and `:`. In safe mode such links were kept instead of being replaced with `#`. Contributes to #726 --- lib/markdown2.py | 3 ++- test/tm-cases/xss_issue726.html | 7 +++++++ test/tm-cases/xss_issue726.opts | 1 + test/tm-cases/xss_issue726.text | 7 +++++++ 4 files changed, 17 insertions(+), 1 deletion(-) create mode 100644 test/tm-cases/xss_issue726.html create mode 100644 test/tm-cases/xss_issue726.opts create mode 100644 test/tm-cases/xss_issue726.text diff --git a/lib/markdown2.py b/lib/markdown2.py index c912e635..5fa8cf58 100755 --- a/lib/markdown2.py +++ b/lib/markdown2.py @@ -1618,7 +1618,8 @@ def _safe_href(self): less_safe = r'#/\.!#$%&\(\)\+,/:;=\?@\[\]^`\{\}\|~' # html encoded colon in a URL still functions as a normal colon, so need to detect those # semicolon at the end is optional in browsers - see #721 - protocol_seperators = [':', r':?', r':?', r':?'] + # numeric references can be zero-padded (:, :) - see #726 + protocol_seperators = [':', r'*3a;?', r'*58;?', r':?'] # dot seperated hostname, optional port number, not followed by protocol seperator domain = r'(?:[{}]+(?:\.[{}]+)*)(?:(?Click me
+ + + + + + diff --git a/test/tm-cases/xss_issue726.opts b/test/tm-cases/xss_issue726.opts new file mode 100644 index 00000000..54de31a8 --- /dev/null +++ b/test/tm-cases/xss_issue726.opts @@ -0,0 +1 @@ +{"safe_mode": "escape"} \ No newline at end of file diff --git a/test/tm-cases/xss_issue726.text b/test/tm-cases/xss_issue726.text new file mode 100644 index 00000000..b276a169 --- /dev/null +++ b/test/tm-cases/xss_issue726.text @@ -0,0 +1,7 @@ +[Click me](javascript:alert(origin)) + +[Click me](javascript:alert(origin)) + +[Click me](javascript:alert(origin)) + +[Click me](javascript:alert(origin)) From 5f8630deb4a363e368af2979e7491dc3d653b1ae Mon Sep 17 00:00:00 2001 From: rmz-oz <262968088+rmz-oz@users.noreply.github.com> Date: Thu, 24 Sep 2026 16:24:35 +0300 Subject: [PATCH 2/2] Add CHANGES entry for #728 --- CHANGES.md | 1 + 1 file changed, 1 insertion(+) diff --git a/CHANGES.md b/CHANGES.md index 4e67d00a..b0c5e7bd 100644 --- a/CHANGES.md +++ b/CHANGES.md @@ -14,6 +14,7 @@ - [pull #705] XSS fixes in links, images, and more - [pull #720] Add `wiki-links` extra for `[[Page Name]]` style links (#221) - [pull #722] Harden URL safety checks and sanitization in safe mode (#721) +- [pull #728] Fix XSS from zero-padded colon entities in link URLs (#726) ## python-markdown2 2.5.5