justhtml 在 1.12.0 之前的版本(即版本 <= 1.11.0)在处理原始文本元素(如 和 )的序列化时,存在一个变异型跨站脚本(mXSS)漏洞。当 函数使用保留这些元素的自定义策略处理 DOM 树时,这些元素内部的文本节点会以未转义的方式原样序列化。这使得攻击者可以构造包含匹配闭合标签序列的受控文本,从而突破原始文本上下文,并在序列化输出中注入任意 HTML。由于默认的清理策略会丢弃 和 元素的内容,因此默认清理策略不受此漏洞影响。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| EmilStenstrom | justhtml | < 1.12.0 |
affected |
1.12.0 |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| EmilStenstrom | justhtml | 0 ~ 1.12.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-7808 | 9.8 CRITICAL | justhtml before 1.16.0 Multiple Security Issues via Sanitization |
| CVE-2026-8445 | 9.8 CRITICAL | justhtml before 1.12.0 Sanitizer Bypass via Markdown |
| CVE-2026-5388 | 9.8 CRITICAL | justhtml before 1.15.0 Multiple Security Issues |
| CVE-2026-9769 | 7.5 HIGH | justhtml before 1.10.0 Denial of Service via deeply nested HTML |
| CVE-2026-4671 | 7.5 HIGH | justhtml before 1.18.0 Denial of Service via CSS Selector |
| CVE-2026-77088 | 6.1 MEDIUM | justhtml 0.9.0 through 1.21.0 Cross-Site Scripting via code-span |
| CVE-2026-74793 | 6.1 MEDIUM | justhtml before 3.11.0 XSS via selectedcontent projection |
| CVE-2026-6827 | 6.1 MEDIUM | justhtml before 1.17.0 Multiple Cross-Site Scripting Vulnerabilities |
| CVE-2026-5751 | 6.1 MEDIUM | justhtml before 1.14.0 Mutation XSS via custom sanitization policies |
| CVE-2026-5389 | 6.1 MEDIUM | justhtml before 1.13.0 XSS via code fence breakout |
No comments yet