XSS Vulnerability in Jodit Editor Affecting Versions Below 4.12.31
CVE-2026-62324

5.4MEDIUM

Key Information:

Vendor

Xdan

Status
Vendor
CVE Published:
31 July 2026

What is CVE-2026-62324?

Jodit Editor is a popular WYSIWYG editor featuring an integrated file browser and image editor. Prior to version 4.12.31, a security flaw existed within the 'sanitizeHTMLElement' method. This method neglected to adequately utilize the 'isDangerousUrl' function to normalize 'javascript:' URLs, allowing attackers to bypass security checks. Variants of the script and malicious inserts, including control-byte prefixes or extraneous whitespace such as tabs and newlines, could potentially lead to the execution of unauthorized scripts when users clicked on crafted links rendered in an application. The vulnerability has been addressed and resolved in the latest update, version 4.12.31.

Affected Version(s)

jodit < 4.12.31

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.