CVE-2026-8630 - justhtml before 1.12.0 Mutation XSS via Raw Text Elements
Brief
CVE ID :CVE-2026-8630
Published : Aug. 23, 2026, 2:16 p. m.
- 2 hours, 54 minutes ago
Description :justhtml before 1.
- 0 (versions and . When a DOM tree is processed by sanitize_dom() using a custom policy that keeps these elements, text nodes inside them are serialized literally without escaping, allowing attacker-controlled text containing the matching closing tag sequence to break out of the raw-text context and inject arbitrary HTML into the serialized output.
The default sanitization policy is not affected because it drops the contents of style and script.
Severity: 6.1
- MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
