{"id":"CVE-2026-5388","aliases":["GHSA-c9vm-hv86-f23r"],"url":"https://o3.security/vulnerability/CVE-2026-5388","summary":"justhtml before 1.15.0 Multiple Security Issues","details":"justhtml before 1.15.0 contains multiple security issues in URL sanitization helpers (clean_url_value/clean_url_in_js_string), HTML serialization, Markdown passthrough (html_passthrough=True), and several custom sanitization-policy edge cases. Depending on configuration, an attacker can bypass sanitization to inject active HTML and JavaScript — for example via encoded javascript: URLs, backslash-based relative URLs resolved as remote hosts, markup-breaking programmatic element/attribute names or HTML comments, raw </textarea> reintroduction through Markdown passthrough, or preserved <style>/<meta http-equiv=refresh>/<base href> tags in custom policies. Most custom-policy issues do not affect the default sanitize=True configuration; they primarily affect helper APIs, programmatic DOM construction, html_passthrough=True, and custom policies/transform pipelines.","published":"2026-08-23T13:34:09.169Z","modified":"2026-08-28T11:30:55.598545822Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"PyPI","name":"justhtml","fixedVersion":"1.15.0"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/5xxx/CVE-2026-5388.json"},{"type":"ADVISORY","url":"https://github.com/EmilStenstrom/justhtml/security/advisories/GHSA-c9vm-hv86-f23r"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-5388"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/justhtml-before-multiple-security-issues"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-28T11:30:55.598545822Z"}}