PT-2026-79774 · Pypi · Justhtml

·

CVE-2026-77088

·

Published

2026-06-25

·

Updated

2026-08-29

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions justhtml versions 0.9.0 through 1.21.0
Description A cross-site scripting issue exists in the to markdown() function. The problem occurs because inline code spans do not recognize blank lines as block boundaries. This allows attackers to inject blank lines into code or pre element text to break the inline span, resulting in sanitized HTML being emitted unescaped and subsequently re-parsed as live Markdown by compliant renderers.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Encoding or Escaping of Output

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-77088
GHSA-JF6W-2MVX-633J

Affected Products

Justhtml