CVE-2026-8445Patch

LOWCVSS 9.3 · CRITICAL

Signal is active with 5 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

justhtml versions <= 1.11.0 (fixed in 1.12.0) do not sufficiently escape HTML-significant characters (angle brackets) in text nodes when converting a parsed document to Markdown via to_markdown(). While a small set of Markdown metacharacters are escaped, characters such as < and > are preserved, so untrusted input that is safe in to_html() — including entity-decoded text (e.g. &lt;script&gt;) or text from RCDATA/RAWTEXT-parsed elements like <title>, <textarea>, <noscript>, and <plaintext> — can be emitted as raw HTML in the Markdown output, enabling a sanitizer bypass and potential cross-site scripting when that output is rendered.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 5 signals
  • Disclosure: 2 classified signals
  • 5 total mentions across 1 day

Deep dive

Activity timeline5 mentions / 1d
01345Mentions · 2026-08-23: 5Patch / Workaround · 2026-08-23: 3Technical Details · 2026-08-23: 508-23
Signal classification2 categories
Patch
360.0%
Disclosure
240.0%
Referenced assets6 URLs
Full discourse5 posts
  • NewNormal Security@NewScanTeam
    Disclosure

    NewNormal Security turns the last 24 hours of CVEs into new detections, every day. 𝗗𝗮𝗶𝗹𝘆 𝗖𝗩𝗘 𝗥𝗲𝗽𝗼𝗿𝘁 — 23 Aug 2026 𝗔𝗱𝗱𝗲𝗱 to NewScan today: 📦 HTML sanitization bypass — unsafe markup can remain active in rendered application content, as seen in justhtml CVE-2026-7808 and CVE-2026-5388 📦 Markdown cross-site scripting — crafted content can render as active HTML, as seen in justhtml CVE-2026-8445 📦 Resource exhaustion — crafted selectors or links can exhaust server-side parsing resources, as seen in justhtml CVE-2026-4671 Test your stack with NewScan — free, self-hosted: https://newnormalsecurity.com/newscan?utm_source=x&utm_medium=social&utm_campaign=daily-cve #infosec #AppSec #XSS #CSO #REDTEAM

    Post summary

    NewNormal Security’s daily report announces the newest CVEs, classifies them by impact, but does not provide evidence of exploitation, PoC code, or mitigation steps.

    0001051
    5 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-8445 Cross-Site Scripting in justhtml &lt;= 1.11.0 via Insufficient HTML E... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-8445 Customizable Vulnerability Alerts: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=4

    Post summary

    The tweet announces CVE‑2026‑8445, a cross‑site scripting flaw in justhtml versions <=1.11.0, and links to vulnerability details, but offers no PoC, exploit, patch, or active exploitation evidence.

    00010136
    4.1K followersView on X
  • ADK Cyber@ADKCyber
    Patch

    justhtml &lt;=1.11.0 contains CVE-2026-8445 (CVSS 9.8) in to_markdown() escaping. Update to 1.12.0 if this library is in your stack: https://nvd.nist.gov/vuln/detail/CVE-2026-8445 via NVD Recent High CVSS #CyberSecurity #InfoSec #Vulnerability #AI #MachineLearning https://t.co/z4EdTnahNz

    Post summary

    The tweet highlights a high‑severity CVE in justhtml with direct remediation instructions, focusing on the patch recommendation rather than exploit details.

    0000037
    93 followersView on X
  • Infoflowcloud@infoflowcloud
    Patch

    🚨*CVE* CVE-2026-8445 justhtml versions &lt;= 1.11.0 (fixed in 1.12.0) do not sufficiently escape HTML-significant characters (angle brackets) in text nodes when converting a parsed document to… https://www.cve.org/CVERecord?id=CVE-2026-8445 ----- Traducción: CVE-2026-8445 las… http://infoflow.cloud`

    Post summary

    The tweet highlights CVE‑2026‑8445, describing an HTML‑escaping flaw in justhtml versions ≤1.11.0, and asserts the vulnerability is addressed in the 1.12.0 release; no PoC or exploitation evidence is provided.

    0000019
    102 followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-8445 justhtml versions &lt;= 1.11.0 (fixed in 1.12.0) do not sufficiently escape HTML-significant characters (angle brackets) in text nodes when converting a parsed document to… https://www.cve.org/CVERecord?id=CVE-2026-8445

    Post summary

    CVE-2026-8445 affects justhtml versions ≤1.11.0 by failing to escape angle brackets in text nodes, enabling potential XSS, and is resolved in 1.12.0.

    00000995
    58.0K followersView on X

Explore more