Critical justhtml Sanitization Bypass Vulnerabilities Discovered
ID: 3916e556-6aff-53a1-8004-208fff98ffbc
STIX ID: report--3916e556-6aff-53a1-8004-208fff98ffbc
Feed Name: ThreatCluster
Threat Score
Multiple critical HTML sanitization vulnerabilities (CVE-2026-5388, CVE-2026-7808, CVE-2026-8445) were published for the justhtml library on 2026-08-23. The flaws (affecting versions prior to 1.15.0/1.16.0) can be abused to bypass sanitization and enable cross-site scripting (XSS); CVSS scores of 9.8 are reported and maintainers recommend immediate upgrades to patched versions to mitigate risk, though no public proof-of-concept or active exploitation has been reported.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
