WYSIWYG Editor Vulnerability in Jodit - Xdan
CVE-2026-65841
5.3MEDIUM
What is CVE-2026-65841?
Jodit Editor, a popular WYSIWYG editor that includes a file browser and image editor, contains a security flaw in versions prior to 4.13.6. This flaw arises from the editor’s 'clean-html' denyTags filter, which fails to properly normalize foreign SVG or MathML script node names. As a result, script elements nested directly within SVG or MathML tags can be executed when the content is loaded, potentially allowing attackers to inject and execute malicious code within the editor's environment. Users are advised to upgrade to version 4.13.6 or later to mitigate this risk.
Affected Version(s)
jodit < 4.13.6
