Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
CVE-2026-41680 affects versions 18.0.0 and 18.0.1 of marked. The python-jupytext package is currently built with version 16.4.2, before the bug was introduced. Later versions are not backwards compatible with 16.4.2, so I have left it alone for now. Also note that marked is used during the build only. It is not included in the binary python3-jupytext package, so there is no runtime vulnerability anyway.