Vulnerabilities & PatchesEmerging1 src
CVE-2026-8445 - justhtml before 1.12.0 Sanitizer Bypass via Markdown
CVE ID : CVE-2026-8445
Published : Aug. 23, 2026, 2:16 p. m.
• 2 hours, 54 minutes ago
Description : justhtml versions are preserved, so untrusted input that is safe in to_html() — including entity-decoded text (e. g. ) or text from RCDATA/RAWTEXT-parsed elements like , , , and — can be emitted as raw HTML in the Markdown output, enabling a sanitizer bypass and potential cross-site scripting when that output is rendered.
Severity: 9.8
• CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...