CVE-2026-5388Disclosure

LOWCVSS 9.3 · CRITICAL

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

justhtml before 1.15.0 contains multiple security issues in URL sanitization helpers (clean_url_value/clean_url_in_js_string), HTML serialization, Markdown passthrough (html_passthrough=True), and several custom sanitization-policy edge cases. Depending on configuration, an attacker can bypass sanitization to inject active HTML and JavaScript — for example via encoded javascript: URLs, backslash-based relative URLs resolved as remote hosts, markup-breaking programmatic element/attribute names or HTML comments, raw </textarea> reintroduction through Markdown passthrough, or preserved <style>/<meta http-equiv=refresh>/<base href> tags in custom policies. Most custom-policy issues do not affect the default sanitize=True configuration; they primarily affect helper APIs, programmatic DOM construction, html_passthrough=True, and custom policies/transform pipelines.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 7 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • General: 3 classified signals
  • Peaked 1d ago at 5 mentions (2026-08-23); latest day: 2
  • 7 total mentions across 2 days

Deep dive

Activity timeline7 mentions / 2d
01345Mentions · 2026-08-23: 5Mentions · 2026-08-24: 2PoC Mentioned / Linked · 2026-08-24: 1Patch / Workaround · 2026-08-23: 1Technical Details · 2026-08-23: 408-2308-24
Signal classification2 categories
Disclosure
457.1%
General
342.9%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-08-235
Disclosure3General2
2026-08-242
Disclosure1General1
Full discourse7 posts
  • ExploitGrid@exploitgrid
    General

    🛡️ #ExploitGrid Daily #Threat Digest Top Vulnerabilities (CVEs) of the day CVE-2026-78167 CVE-2026-78155 CVE-2026-78211 CVE-2026-78169 CVE-2026-5388 ..🧵👇

    Post summary

    A daily digest lists several CVE identifiers without any exploit, patch, or technical detail information.

    1001038
    38 followersView on X
  • ExploitGrid@exploitgrid
    Disclosure

    [CVE] CVE-2026-5388 [HIGH PRIORITY] #justhtml before 1.15.0 Multiple Security Issues 🔗 https://exploitgrid.net/cve/CVE-2026-5388

    Post summary

    The post announces CVE-2026-5388 as a high‑priority vulnerability affecting justhtml before version 1.15.0, noting multiple security issues but providing no technical details or remediation guidance.

    1000019
    38 followersView on X
  • NewNormal Security@NewScanTeam
    General

    NewNormal Security turns the last 24 hours of CVEs into new detections, every day. 𝗗𝗮𝗶𝗹𝘆 𝗖𝗩𝗘 𝗥𝗲𝗽𝗼𝗿𝘁 — 23 Aug 2026 𝗔𝗱𝗱𝗲𝗱 to NewScan today: 📦 HTML sanitization bypass — unsafe markup can remain active in rendered application content, as seen in justhtml CVE-2026-7808 and CVE-2026-5388 📦 Markdown cross-site scripting — crafted content can render as active HTML, as seen in justhtml CVE-2026-8445 📦 Resource exhaustion — crafted selectors or links can exhaust server-side parsing resources, as seen in justhtml CVE-2026-4671 Test your stack with NewScan — free, self-hosted: https://newnormalsecurity.com/newscan?utm_source=x&utm_medium=social&utm_campaign=daily-cve #infosec #AppSec #XSS #CSO #REDTEAM

    Post summary

    NewNormal Security’s daily CVE report enumerates several recent justhtml vulnerabilities with brief impact descriptions, but offers no PoCs, exploits, patches, or evidence of active exploitation.

    0001051
    5 followersView on X
  • ADK Cyber@ADKCyber
    Disclosure

    CVE-2026-5388 (CVSS 9.8) impacts justhtml &lt;1.15.0 in URL sanitization, HTML serialization, and Markdown handling. Check dependencies and update promptly. https://nvd.nist.gov/vuln/detail/CVE-2… via NVD Recent High CVSS #CyberSecurity #InfoSec #Vulnerability #AI #MachineLearning https://t.co/1ht9fXOajs

    Post summary

    The tweet reports CVE-2026-5388, a high‑severity vulnerability in justhtml <1.15.0 affecting URL sanitization, HTML serialization, and Markdown handling, and urges users to update dependencies to mitigate the risk.

    0000038
    93 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-5388 justhtml before 1.15.0 contains multiple security issues in URL sanitization helpers (clean_url_value/clean_url_in_js_string), HTML serialization, Markdown passthrough … https://www.cve.org/CVERecord?id=CVE-2026-5388 ----- Traducción: CVE-2026-5388 jus… http://infoflow.cloud`

    Post summary

    The post announces CVE‑2026‑5388, a vulnerability in justhtml before 1.15.0 affecting URL sanitization, HTML serialization, and Markdown passthrough, but offers no PoC, exploit, or patch details.

    0000027
    102 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-5388 justhtml before 1.15.0 contains multiple security issues in URL sanitization helpers (clean_url_value/clean_url_in_js_string), HTML serialization, Markdown passthrough … https://www.cve.org/CVERecord?id=CVE-2026-5388

    Post summary

    The post announces CVE-2026-5388 affecting justhtml versions prior to 1.15.0, noting multiple security issues in URL sanitization helpers, HTML serialization, and Markdown passthrough.

    000001.8K
    58.0K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-5388 Multiple Vulnerabilities in justhtml 1.15.0 Allow HTML and JavaScript Injection https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-5388

    Post summary

    The post reports that justhtml 1.15.0 contains multiple vulnerabilities enabling HTML and JavaScript injection, providing a link for more details but no additional exploit or mitigation information.

    00000125
    4.1K followersView on X

Explore more