PT-2026-79775 · Justhtml · Justhtml
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
justhtml versions prior to 1.16.0
Description
Multiple HTML sanitization bypass issues allow active or dangerous content, such as script or style tags, to survive the sanitization process, potentially leading to cross-site scripting. These issues primarily affect advanced usage scenarios rather than the default sanitization path. Technical causes include the mutation or reuse of sanitization policy objects, which can weaken subsequent sanitization. Additionally, programmatic DOM input provided to the
sanitize() and sanitize dom() functions may fail to detect mixed-case tag names (e.g., ScRiPt, StYlE). Other vectors include crafted programmatic doctype names that serialize into active markup and custom policies preserving SVG or MathML that may allow animation elements, presentation attributes with external url(...) references, or DOM trees mislabeled as namespace="html" to bypass foreign-content checks.Recommendations
Update justhtml to version 1.16.0.
Exploit
Fix
XSS
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Justhtml