Junglewise Threat Intelligence

CVE-2026-77088: justhtml to_markdown() cross-site scripting in code span

CVE-2026-77088 · Severity: medium · CVSS 6.1 · Published 2026-08-23

Technologies: Emil Stenstrom Justhtml.

Executive brief

justhtml is a Python library that converts HTML to Markdown format, commonly used in systems that process user-generated HTML content. Versions 0.9.0 through 1.21.0 fail to properly handle blank lines within code blocks, allowing attackers to inject malicious HTML (such as JavaScript event handlers) that bypasses sanitization and executes in the browser. This can lead to account compromise, session hijacking, or stealing sensitive user data.

Technical details

The vulnerability is a cross-site scripting (CWE-79) flaw arising from improper output encoding (CWE-116). The to_markdown() function converts HTML code and pre elements to Markdown inline code spans, using backtick fences to protect the content. However, the implementation fails to account for blank lines (\n\n), which are block boundaries in Markdown that terminate inline code spans. An attacker can inject a blank line into sanitized HTML code elements; when converted to Markdown, the blank line breaks the fence, leaving subsequent attacker-controlled text unescaped. Compliant Markdown renderers then re-parse this text as raw HTML, executing any embedded JavaScript. The vulnerability is reachable by default: the library sanitizes HTML but preserves code/pre elements and their text content, and the payload can be smuggled through character reference encoding (e.g., <img …>) to survive sanitization. A patch is available in version 1.22.0.

Affected products

  • Emil Stenstrom justhtml 0.9.0 through 1.21.0

Timeline

  • 2026-05-22: disclosed: GitHub Security Advisory published
  • 2026-08-23: advisory: CVE-2026-77088 published on NVD
  • 2026-05-22: patched: Fix available in version 1.22.0

References