CVE-2026-8630
justhtml before 1.12.0 Mutation XSS via Raw Text Elements
justhtml before 1.12.0 (versions <= 1.11.0) contains a mutation cross-site scripting (mXSS) vulnerability in the serialization of raw-text elements such as <style> and <script>. When a DOM tree is processed by sanitize_dom() using a custom policy that keeps these elements, text nodes inside them are serialized literally without escaping, allowing attacker-controlled text containing the matching closing tag sequence to break out of the raw-text context and inject arbitrary HTML into the serialized output. The default sanitization policy is not affected because it drops the contents of style and script.
| CWE | CWE-79 |
| Vendor | emilstenstrom |
| Product | justhtml |
| Published | Aug 23, 2026 |
Get instant alerts for emilstenstrom justhtml
Be the first to know when new medium vulnerabilities affecting emilstenstrom justhtml are published โ delivered to Slack, Telegram or Discord.
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N