justhtml 1.13.0 及更早版本在使用自定义的 SanitizationPolicy(保留外部命名空间,例如设置 drop_foreign_namespaces=False 并允许 SVG/MathML 元素或原始文本容器如 <style>)时,存在解析器差异/突变型跨站脚本(mXSS)漏洞。经过特殊构造的输入在经过 sanitization 处理后,可能生成看似安全的标记,但在被浏览器或其他 HTML 解析器重新解析时会变得不安全,从而导致标记注入。默认的默认安全配置(sanitize=True)不受影
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| EmilStenstrom | justhtml | < 1.14.0 |
affected |
1.14.0 |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| EmilStenstrom | justhtml | 0 ~ 1.14.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-7808 | 9.8 CRITICAL | justhtml before 1.16.0 Multiple Security Issues via Sanitization |
| CVE-2026-8445 | 9.8 CRITICAL | justhtml before 1.12.0 Sanitizer Bypass via Markdown |
| CVE-2026-5388 | 9.8 CRITICAL | justhtml before 1.15.0 Multiple Security Issues |
| CVE-2026-9769 | 7.5 HIGH | justhtml before 1.10.0 Denial of Service via deeply nested HTML |
| CVE-2026-4671 | 7.5 HIGH | justhtml before 1.18.0 Denial of Service via CSS Selector |
| CVE-2026-77088 | 6.1 MEDIUM | justhtml 0.9.0 through 1.21.0 Cross-Site Scripting via code-span |
| CVE-2026-74793 | 6.1 MEDIUM | justhtml before 3.11.0 XSS via selectedcontent projection |
| CVE-2026-6827 | 6.1 MEDIUM | justhtml before 1.17.0 Multiple Cross-Site Scripting Vulnerabilities |
| CVE-2026-8630 | 6.1 MEDIUM | justhtml before 1.12.0 Mutation XSS via Raw Text Elements |
| CVE-2026-5389 | 6.1 MEDIUM | justhtml before 1.13.0 XSS via code fence breakout |
No comments yet