PT-2026-79775 · Justhtml · Justhtml

·

CVE-2026-7808

·

Published

2026-04-14

·

Updated

2026-08-24

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions justhtml versions prior to 1.16.0
Description Multiple HTML sanitization bypass issues allow active or dangerous content, such as script or style tags, to survive the sanitization process, potentially leading to cross-site scripting. These issues primarily affect advanced usage scenarios rather than the default sanitization path. Technical causes include the mutation or reuse of sanitization policy objects, which can weaken subsequent sanitization. Additionally, programmatic DOM input provided to the sanitize() and sanitize dom() functions may fail to detect mixed-case tag names (e.g., ScRiPt, StYlE). Other vectors include crafted programmatic doctype names that serialize into active markup and custom policies preserving SVG or MathML that may allow animation elements, presentation attributes with external url(...) references, or DOM trees mislabeled as namespace="html" to bypass foreign-content checks.
Recommendations Update justhtml to version 1.16.0.

Exploit

Fix

XSS

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-7808
GHSA-4P64-V8F5-R2GX

Affected Products

Justhtml