justhtml 版本 0.9.0 至 1.21.0 在 函数中存在跨站脚本(XSS)漏洞。该漏洞源于对行内代码片段(inline code spans)的处理未将空行视为块级边界。攻击者可通过在代码或 元素文本中注入空行,破坏行内代码片段的完整性,从而导致经过安全过滤的 HTML 内容被作为未转义文本直接输出,并被符合规范的 Markdown 渲染引擎重新解析为可执行的 Markdown 语法,引发 XSS 攻击。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| EmilStenstrom | justhtml | < 0.9.0 |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| EmilStenstrom | justhtml | 0 ~ 0.9.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-7808 | 9.8 CRITICAL | justhtml before 1.16.0 Multiple Security Issues via Sanitization |
| CVE-2026-8445 | 9.8 CRITICAL | justhtml before 1.12.0 Sanitizer Bypass via Markdown |
| CVE-2026-5388 | 9.8 CRITICAL | justhtml before 1.15.0 Multiple Security Issues |
| CVE-2026-9769 | 7.5 HIGH | justhtml before 1.10.0 Denial of Service via deeply nested HTML |
| CVE-2026-4671 | 7.5 HIGH | justhtml before 1.18.0 Denial of Service via CSS Selector |
| CVE-2026-74793 | 6.1 MEDIUM | justhtml before 3.11.0 XSS via selectedcontent projection |
| CVE-2026-6827 | 6.1 MEDIUM | justhtml before 1.17.0 Multiple Cross-Site Scripting Vulnerabilities |
| CVE-2026-8630 | 6.1 MEDIUM | justhtml before 1.12.0 Mutation XSS via Raw Text Elements |
| CVE-2026-5751 | 6.1 MEDIUM | justhtml before 1.14.0 Mutation XSS via custom sanitization policies |
| CVE-2026-5389 | 6.1 MEDIUM | justhtml before 1.13.0 XSS via code fence breakout |
No comments yet