๐Ÿ” CVE Alert

CVE-2026-62324

MEDIUM 5.4

Jodit has incomplete javascript: scheme normalization in sanitizeHTMLElement href check that allows link XSS

CVSS Score
5.4
EPSS Score
0.0%
EPSS Percentile
0th

Jodit Editor is a WYSIWYG editor with a built-in file browser & image editor. Prior to 4.12.31, Jodit's sanitizeHTMLElement method fails to use isDangerousUrl to normalize javascript: href values before checking the scheme, allowing case variants, control-byte prefixes, and embedded tabs or newlines to bypass filtering and execute attacker-controlled script when a victim clicks a stored link rendered by an application. This issue is fixed in version 4.12.31.

CWE CWE-79 CWE-83
Vendor xdan
Product jodit
Published Jul 31, 2026
Stay Ahead of the Next One

Get instant alerts for xdan jodit

Be the first to know when new medium vulnerabilities affecting xdan jodit are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None

Affected Versions

xdan / jodit
< 4.12.31

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/xdan/jodit/security/advisories/GHSA-j839-gqq4-gf9j github.com: https://github.com/xdan/jodit/commit/5fba6ef2381d151d7cb8e3c5ad0b9996af0f97b0 github.com: https://github.com/xdan/jodit/releases/tag/4.12.31