Executive brief
justhtml is a library used to sanitize and process HTML content programmatically. The library contains a vulnerability in how it serializes HTML when custom sanitization policies allow raw-text elements like style and script tags. An attacker can craft malicious text content within these elements that breaks out of the raw-text context and injects arbitrary HTML, potentially leading to script execution in applications that use non-default sanitization policies.
Technical details
This is a mutation XSS (mXSS) vulnerability in the serialize.py module's handling of raw-text elements. The root cause is that text nodes within style and script elements are serialized verbatim without HTML escaping via the _serialize_text_for_parent() function. When a DOM tree is processed through sanitize_dom() with a custom policy that preserves these elements, an attacker can inject text containing a matching closing tag sequence (e.g., "</style>" within a style element) to break out of the raw-text context and inject arbitrary HTML. The attack requires either programmatic DOM construction with attacker input or a custom sanitization policy that retains script/style elements; the default policy is not affected. Patched in version 1.12.0.
Affected products
- justhtml justhtml <= 1.11.0
Timeline
- 2026-03-18: disclosed
- 2026-03-18: patched: Version 1.12.0 released