PT-2026-79774 · Pypi · Justhtml
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
justhtml versions 0.9.0 through 1.21.0
Description
A cross-site scripting issue exists in the
to markdown() function. The problem occurs because inline code spans do not recognize blank lines as block boundaries. This allows attackers to inject blank lines into code or pre element text to break the inline span, resulting in sanitized HTML being emitted unescaped and subsequently re-parsed as live Markdown by compliant renderers.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Improper Encoding or Escaping of Output
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Justhtml