Junglewise Threat Intelligence

CVE-2026-8630: justhtml mutation XSS in raw-text element serialization

CVE-2026-8630 · Severity: medium · CVSS 6.1 · Published 2026-08-23

Technologies: Justhtml.

Executive brief

justhtml is a library used to sanitize and process HTML content programmatically. The library contains a vulnerability in how it serializes HTML when custom sanitization policies allow raw-text elements like style and script tags. An attacker can craft malicious text content within these elements that breaks out of the raw-text context and injects arbitrary HTML, potentially leading to script execution in applications that use non-default sanitization policies.

Technical details

This is a mutation XSS (mXSS) vulnerability in the serialize.py module's handling of raw-text elements. The root cause is that text nodes within style and script elements are serialized verbatim without HTML escaping via the _serialize_text_for_parent() function. When a DOM tree is processed through sanitize_dom() with a custom policy that preserves these elements, an attacker can inject text containing a matching closing tag sequence (e.g., "</style>" within a style element) to break out of the raw-text context and inject arbitrary HTML. The attack requires either programmatic DOM construction with attacker input or a custom sanitization policy that retains script/style elements; the default policy is not affected. Patched in version 1.12.0.

Affected products

  • justhtml justhtml <= 1.11.0

Timeline

  • 2026-03-18: disclosed
  • 2026-03-18: patched: Version 1.12.0 released

References