logo

Critical justhtml Sanitization Bypass Vulnerabilities Discovered

ID: 3916e556-6aff-53a1-8004-208fff98ffbc

STIX ID: report--3916e556-6aff-53a1-8004-208fff98ffbc

Feed Name: ThreatCluster

Threat Score
75/100

Date Published: 2026-08-23

Date Updated: 2026-08-24

...
...

Multiple critical HTML sanitization vulnerabilities (CVE-2026-5388, CVE-2026-7808, CVE-2026-8445) were published for the justhtml library on 2026-08-23. The flaws (affecting versions prior to 1.15.0/1.16.0) can be abused to bypass sanitization and enable cross-site scripting (XSS); CVSS scores of 9.8 are reported and maintainers recommend immediate upgrades to patched versions to mitigate risk, though no public proof-of-concept or active exploitation has been reported.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.