Sanitizer Bypass in JustHTML Versions by Emil Stenstrom
CVE-2026-8445
9.3CRITICAL
What is CVE-2026-8445?
The vulnerability in JustHTML versions up to 1.11.0 arises from inadequate escaping of HTML-specific characters during the conversion of documents to Markdown. This issue allows untrusted input to be included as raw HTML in the Markdown output, specifically enabling potential cross-site scripting attacks. Users are encouraged to upgrade to version 1.12.0, where this issue has been addressed.
Affected Version(s)
justhtml 0 < 1.12.0
justhtml 1.12.0
