CVE-2026-8630Disclosure

LOWCVSS 5.1 · MEDIUM

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

justhtml before 1.12.0 (versions <= 1.11.0) contains a mutation cross-site scripting (mXSS) vulnerability in the serialization of raw-text elements such as <style> and <script>. When a DOM tree is processed by sanitize_dom() using a custom policy that keeps these elements, text nodes inside them are serialized literally without escaping, allowing attacker-controlled text containing the matching closing tag sequence to break out of the raw-text context and inject arbitrary HTML into the serialized output. The default sanitization policy is not affected because it drops the contents of style and script.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-08-23: 3Technical Details · 2026-08-23: 308-23
Signal classification1 categories
Disclosure
3100.0%
Referenced assets2 URLs
Full discourse3 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-8630 Mutation XSS in justhtml 1.11.0 and Earlier via Raw-Text Element Serialization https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-8630

    Post summary

    CVE-2026-8630 is a mutation XSS flaw in justhtml 1.11.0 and earlier caused by raw‑text element serialization, as disclosed with technical details but without an exploit or patch referenced.

    00001137
    4.1K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-8630 justhtml before 1.12.0 (versions &lt;= 1.11.0) contains a mutation cross-site scripting (mXSS) vulnerability in the serialization of raw-text elements such as

    Post summary

    The note announces that CVE‑2026‑8630 is a mutation XSS flaw in justhtml (versions <= 1.11.0) related to raw‑text serialization.

    0000018
    102 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-8630 justhtml before 1.12.0 (versions &lt;= 1.11.0) contains a mutation cross-site scripting (mXSS) vulnerability in the serialization of raw-text elements such as &lt;style&gt; and … https://www.cve.org/CVERecord?id=CVE-2026-8630

    Post summary

    The post announces CVE‑2026‑8630, a mutation XSS flaw in justhtml versions <=1.11.0 that occurs during serialization of raw‑text elements such as <style>, with no PoC, exploit code, or patch information provided.

    000001.2K
    58.0K followersView on X

Explore more