Ghostwire

CVE-2026-8630: justhtml before 1.12.0 (versions and . When a DOM tree is processed by sanitize_dom() using a custom policy that keeps...

MEDIUM CVSS 0.0

Published: August 23, 2026 | Last Modified: August 24, 2026

Description

justhtml before 1.12.0 (versions and . When a DOM tree is processed by sanitize_dom() using a custom policy that keeps these elements, text nodes inside them are serialized literally without escaping, allowing attacker-controlled text containing the matching closing tag sequence to break out of the raw-text context and inject arbitrary HTML into the serialized output. The default sanitization policy is not affected because it drops the contents of style and script.

Ghostwire Analysis — What This Means Practically

This analysis is generated by Ghostwire from NVD, CISA KEV, EPSS, and open-source intelligence data. Verify findings through primary sources before acting.

Security Coverage (1 articles)

References