CVE-2026-8630
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
Summary
justhtml before 1.12.0 (versions <= 1.11.0) contains a mutation cross-site scripting (mXSS) vulnerability in the serialization of raw-text elements such as <style> and <script>. When a DOM tree is processed by sanitize_dom() using a custom policy that keeps these elements, text nodes inside them are serialized literally without escaping, allowing attacker-controlled text containing the matching closing tag sequence to break out of the raw-text context and inject arbitrary HTML into the serialized output. The default sanitization policy is not affected because it drops the contents of style and script.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| EmilStenstrom | justhtml | 0 < 1.12.0 | affected |
| EmilStenstrom | justhtml | 1.12.0 | unaffected |
Weaknesses
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
References
- https://github.com/EmilStenstrom/justhtml/security/advisories/GHSA-qvc2-mg72-jjhx
- https://www.vulncheck.com/advisories/justhtml-before-mutation-xss-via-raw-text-elements
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.