在 justhtml 1.17.0 版本之前,其在 sanitization(净化)、serialization(序列化)以及程序化 DOM 处理方面存在多个安全问题。当自定义策略允许保留外部命名空间(如 SVG 或 MathML)时,危险内容(例如 HTML 集成点:SVG 中的 、MathML 中的 )以及利用解析器差异的 mutation-XSS(变异型跨站脚本)载荷可能绕过净化机制,并在重新解析后转换为可执行的 HTML 代码。此外,SVG 的 属性以及被保留的 标签仍可能导致资源加载型 CSS 攻击(如
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| EmilStenstrom | justhtml | < 1.16.0 |
affected |
1.16.0 |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| EmilStenstrom | justhtml | 0 ~ 1.16.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-7808 | 9.8 CRITICAL | justhtml before 1.16.0 Multiple Security Issues via Sanitization |
| CVE-2026-8445 | 9.8 CRITICAL | justhtml before 1.12.0 Sanitizer Bypass via Markdown |
| CVE-2026-5388 | 9.8 CRITICAL | justhtml before 1.15.0 Multiple Security Issues |
| CVE-2026-9769 | 7.5 HIGH | justhtml before 1.10.0 Denial of Service via deeply nested HTML |
| CVE-2026-4671 | 7.5 HIGH | justhtml before 1.18.0 Denial of Service via CSS Selector |
| CVE-2026-77088 | 6.1 MEDIUM | justhtml 0.9.0 through 1.21.0 Cross-Site Scripting via code-span |
| CVE-2026-74793 | 6.1 MEDIUM | justhtml before 3.11.0 XSS via selectedcontent projection |
| CVE-2026-8630 | 6.1 MEDIUM | justhtml before 1.12.0 Mutation XSS via Raw Text Elements |
| CVE-2026-5751 | 6.1 MEDIUM | justhtml before 1.14.0 Mutation XSS via custom sanitization policies |
| CVE-2026-5389 | 6.1 MEDIUM | justhtml before 1.13.0 XSS via code fence breakout |
No comments yet