← Back to feed
Vulnerabilities & PatchesEmerging1 sourceAug 23, 2026 · 14:16via CVEFeed

CVE-2026-8445 - justhtml before 1.12.0 Sanitizer Bypass via Markdown

Brief

CVE ID : CVE-2026-8445

Published : Aug. 23, 2026, 2:16 p. m.

  • 2 hours, 54 minutes ago

Description : justhtml versions are preserved, so untrusted input that is safe in to_html() — including entity-decoded text (e. g. ) or text from RCDATA/RAWTEXT-parsed elements like , , , and — can be emitted as raw HTML in the Markdown output, enabling a sanitizer bypass and potential cross-site scripting when that output is rendered.

Severity: 9.8

  • CRITICAL

Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Read more on CVEFeed