Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 24 Aug 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sun, 23 Aug 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Emilstenstrom
Emilstenstrom justhtml |
|
| Vendors & Products |
Emilstenstrom
Emilstenstrom justhtml |
Sun, 23 Aug 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | justhtml versions 1.13.0 and earlier contain a parser-differential / mutation cross-site scripting (mXSS) vulnerability when using a custom SanitizationPolicy that preserves foreign namespaces (e.g., drop_foreign_namespaces=False with allowlisted SVG/MathML elements or raw-text containers such as <style>). Specially crafted input can sanitize into markup that appears safe but becomes unsafe when re-parsed by a browser or another HTML parser, allowing markup injection. The default safe configuration (sanitize=True) is not affected. Fixed in 1.14.0. | |
| Title | justhtml before 1.14.0 Mutation XSS via custom sanitization policies | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-24T19:03:33.747Z
Reserved: 2026-04-07T15:54:18.686Z
Link: CVE-2026-5751
Updated: 2026-08-24T19:03:30.684Z
Status : Deferred
Published: 2026-08-23T14:16:53.807
Modified: 2026-08-26T17:10:53.700
Link: CVE-2026-5751
No data.
OpenCVE Enrichment
Updated: 2026-08-23T16:39:44Z