Junglewise Threat Intelligence

CVE-2026-5751: justhtml mutation cross-site scripting in custom sanitization policies

CVE-2026-5751 · Severity: medium · CVSS 6.1 · Published 2026-08-23

Technologies: Justhtml.

Executive brief

justhtml is a Python library for sanitizing HTML content to prevent security attacks. Versions 1.13.0 and earlier contain a flaw in custom sanitization policies that can allow attackers to inject malicious markup when foreign namespaces (SVG, MathML) or raw-text containers are preserved. The injected code appears safe initially but becomes executable when re-parsed, potentially compromising users who view the content. The default secure configuration is unaffected.

Technical details

A mutation XSS (mXSS) vulnerability exists in justhtml's custom sanitization policies when drop_foreign_namespaces=False or when foreign elements/raw-text containers are allowlisted. The vulnerability is a parser-differential attack: specially crafted HTML input sanitizes to markup that appears benign under one parser but becomes malicious when re-parsed by a browser or alternative HTML parser. The attack requires custom policy configuration; the default sanitize=True mode is not vulnerable. Attack vector is network-based with user interaction (viewing content). Fixed in version 1.14.0.

Affected products

  • justhtml justhtml <=1.13.0

Timeline

  • 2026-04-05: disclosed: GitHub Security Advisory GHSA-r758-8hxw-4845 published
  • 2026-08-23: patched: Fixed in justhtml 1.14.0

References