justhtml versions before 1.13.0 contain a cross-site scripting vulnerability in the to_markdown() function when serializing attacker-controlled pre content. Attackers can place backticks inside sanitized pre elements to break out of fixed-length code fences, allowing raw HTML to execute when the generated Markdown is rendered by CommonMark or GFM-style renderers.
Metrics
Affected Vendors & Products
References
History
Sun, 23 Aug 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Emilstenstrom
Emilstenstrom justhtml |
|
| Vendors & Products |
Emilstenstrom
Emilstenstrom justhtml |
Sun, 23 Aug 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | justhtml versions before 1.13.0 contain a cross-site scripting vulnerability in the to_markdown() function when serializing attacker-controlled pre content. Attackers can place backticks inside sanitized pre elements to break out of fixed-length code fences, allowing raw HTML to execute when the generated Markdown is rendered by CommonMark or GFM-style renderers. | |
| Title | justhtml before 1.13.0 XSS via code fence breakout | |
| Weaknesses | CWE-80 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-23T13:34:09.865Z
Reserved: 2026-04-01T21:14:36.435Z
Link: CVE-2026-5389
No data.
Status : Received
Published: 2026-08-23T14:16:53.647
Modified: 2026-08-23T14:16:53.647
Link: CVE-2026-5389
No data.
OpenCVE Enrichment
Updated: 2026-08-23T16:39:45Z