justhtml 1.13.0 之前的版本中存在跨站脚本(XSS)漏洞。在调用 to_markdown() 函数序列化用户可控的 <pre> 内容时,攻击者可以在已处理的 <pre> 元素中插入反引号(backticks),从而突破固定长度的代码围栏(code fences)。当生成的 Markdown 被 CommonMark 或 GitHub Flavored Markdown (GFM) 风格的渲染器渲染时,会导致原始 HTML 被执行。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| EmilStenstrom | justhtml | < 1.13.0 |
affected |
1.13.0 |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| EmilStenstrom | justhtml | 0 ~ 1.13.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-7808 | 9.8 CRITICAL | justhtml before 1.16.0 Multiple Security Issues via Sanitization |
| CVE-2026-8445 | 9.8 CRITICAL | justhtml before 1.12.0 Sanitizer Bypass via Markdown |
| CVE-2026-5388 | 9.8 CRITICAL | justhtml before 1.15.0 Multiple Security Issues |
| CVE-2026-9769 | 7.5 HIGH | justhtml before 1.10.0 Denial of Service via deeply nested HTML |
| CVE-2026-4671 | 7.5 HIGH | justhtml before 1.18.0 Denial of Service via CSS Selector |
| CVE-2026-77088 | 6.1 MEDIUM | justhtml 0.9.0 through 1.21.0 Cross-Site Scripting via code-span |
| CVE-2026-74793 | 6.1 MEDIUM | justhtml before 3.11.0 XSS via selectedcontent projection |
| CVE-2026-6827 | 6.1 MEDIUM | justhtml before 1.17.0 Multiple Cross-Site Scripting Vulnerabilities |
| CVE-2026-8630 | 6.1 MEDIUM | justhtml before 1.12.0 Mutation XSS via Raw Text Elements |
| CVE-2026-5751 | 6.1 MEDIUM | justhtml before 1.14.0 Mutation XSS via custom sanitization policies |
No comments yet