Vulnerabilities & PatchesEmerging1 src
CVE-2026-8630 - justhtml before 1.12.0 Mutation XSS via Raw Text Elements
CVE ID :CVE-2026-8630
Published : Aug. 23, 2026, 2:16 p. m.
• 2 hours, 54 minutes ago
Description :justhtml before 1. 12. 0 (versions and . When a DOM tree is processed by sanitize_dom() using a custom policy that keeps these elements, text nodes inside them are serialized literally without escaping, allowing attacker-controlled text containing the matching closing tag sequence to break out of the raw-text context and inject arbitrary HTML into the serialized output.
The default sanitization policy is not affected because it drops the contents of style and script.
Severity: 6.1
• MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...