{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/justhtml--1.11.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-5388"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["justhtml (1.15.0)","justhtml (\u003c= 1.11.0)","justhtml"],"_cs_severities":["critical"],"_cs_tags":["xss","injection","library-vulnerability"],"_cs_type":"advisory","_cs_vendors":["justhtml"],"content_html":"\u003cp\u003eThe justhtml library, specifically versions prior to 1.15.0, contains critical security flaws within its URL sanitization helpers (clean_url_value and clean_url_in_js_string), HTML serialization logic, and Markdown passthrough functionality. These vulnerabilities enable attackers to bypass sanitization filters and inject active HTML and JavaScript content.\u003c/p\u003e\n\u003cp\u003eThe attack surface is primarily driven by misconfigurations or the use of helper APIs and custom policy pipelines. Attackers can leverage these flaws through techniques such as encoded javascript: pseudo-protocols, malformed relative URLs resolved as remote hosts, and the injection of prohibited elements like \u0026lt;style\u0026gt;, \u0026lt;meta http-equiv=refresh\u0026gt;, and \u0026lt;base href\u0026gt; tags. While default configurations are safer, users relying on custom sanitization policies, programmatic DOM construction, or the html_passthrough=True parameter are at the highest risk. These flaws effectively undermine the security boundary of the library, potentially leading to Stored or Reflected Cross-Site Scripting (XSS) depending on the integration within downstream applications.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of these vulnerabilities allows for the execution of arbitrary JavaScript within the context of a victim's browser session. Depending on the target application's sensitivity, this can lead to session hijacking, unauthorized actions performed on behalf of the user, or the exfiltration of sensitive data. Because this is a library-level flaw, the impact is highly dependent on how the library is utilized within specific web applications and CMS frameworks. Organizations utilizing justhtml for content sanitization or Markdown processing should assess whether their specific implementation utilizes the affected helper APIs or custom policies.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the justhtml library to version 1.15.0 or later to patch these sanitization flaws.\u003c/li\u003e\n\u003cli\u003eAudit applications using the justhtml library, specifically searching for the use of html_passthrough=True or custom sanitization-policy configurations.\u003c/li\u003e\n\u003cli\u003eImplement secondary Content Security Policy (CSP) headers to mitigate the impact of potential XSS vulnerabilities in the event of a bypass.\u003c/li\u003e\n\u003cli\u003eReview existing integration code to ensure that clean_url_value and clean_url_in_js_string are not being misused in contexts where user input can influence the URL scheme or hostname.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-23T17:37:37Z","date_published":"2026-08-23T15:37:25Z","id":"https://feed.craftedsignal.io/briefs/2026-08-justhtml-xss/","summary":"The justhtml library before version 1.15.0 contains multiple vulnerabilities in URL sanitization, HTML serialization, and Markdown passthrough that allow attackers to inject malicious HTML and JavaScript.","title":"Multiple Sanitization Bypass Vulnerabilities in justhtml Library","url":"https://feed.craftedsignal.io/briefs/2026-08-justhtml-xss/"}],"language":"en","title":"CraftedSignal Threat Feed - Justhtml (\u003c= 1.11.0)","version":"https://jsonfeed.org/version/1.1"}