{"id":"CVE-2026-8630","aliases":["GHSA-qvc2-mg72-jjhx"],"url":"https://o3.security/vulnerability/CVE-2026-8630","summary":"justhtml before 1.12.0 Mutation XSS via Raw Text Elements","details":"justhtml before 1.12.0 (versions <= 1.11.0) contains a mutation cross-site scripting (mXSS) vulnerability in the serialization of raw-text elements such as <style> and <script>. When a DOM tree is processed by sanitize_dom() using a custom policy that keeps these elements, text nodes inside them are serialized literally without escaping, allowing attacker-controlled text containing the matching closing tag sequence to break out of the raw-text context and inject arbitrary HTML into the serialized output. The default sanitization policy is not affected because it drops the contents of style and script.","published":"2026-08-23T13:34:14.556Z","modified":"2026-08-28T11:30:52.593422391Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"PyPI","name":"justhtml","fixedVersion":"1.12.0"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/8xxx/CVE-2026-8630.json"},{"type":"ADVISORY","url":"https://github.com/EmilStenstrom/justhtml/security/advisories/GHSA-qvc2-mg72-jjhx"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-8630"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/justhtml-before-mutation-xss-via-raw-text-elements"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-28T11:30:52.593422391Z"}}