XSS Vulnerability in Jodit Editor Affecting Versions Below 4.12.31
CVE-2026-62324
5.4MEDIUM
What is CVE-2026-62324?
Jodit Editor is a popular WYSIWYG editor featuring an integrated file browser and image editor. Prior to version 4.12.31, a security flaw existed within the 'sanitizeHTMLElement' method. This method neglected to adequately utilize the 'isDangerousUrl' function to normalize 'javascript:' URLs, allowing attackers to bypass security checks. Variants of the script and malicious inserts, including control-byte prefixes or extraneous whitespace such as tabs and newlines, could potentially lead to the execution of unauthorized scripts when users clicked on crafted links rendered in an application. The vulnerability has been addressed and resolved in the latest update, version 4.12.31.
Affected Version(s)
jodit < 4.12.31
