CVE-2026-77088: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in EmilStenstrom justhtml
Description
justhtml versions 0.9.0 through 1.21.0 have a cross-site scripting (XSS) vulnerability in the to_markdown() function. This occurs because inline code spans do not properly handle blank lines as block boundaries, allowing attackers to inject blank lines into code or pre element text. This causes sanitized HTML to be emitted unescaped and re-parsed as live Markdown by compliant renderers, potentially leading to XSS attacks.
CVSS v4.0
Score 5.3medium
Affected software
EmilStenstrom
justhtml
pkg:github/emilstenstrom/justhtmlRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-77088 describes a cross-site scripting vulnerability in EmilStenstrom's justhtml library versions 0.9.0 through 1.21.0. The flaw exists in the to_markdown() function where inline code spans fail to treat blank lines as block boundaries. Attackers can exploit this by injecting blank lines into code or pre element text, which breaks the inline span and causes sanitized HTML to be output without escaping. This unescaped HTML is then re-parsed as live Markdown by compliant Markdown renderers, enabling injection of malicious scripts.
Potential Impact
The vulnerability allows an attacker to inject malicious content that is executed in the context of users viewing Markdown rendered by justhtml. This can lead to cross-site scripting attacks, potentially compromising user data or session information. The CVSS 4.0 score is 5.3 (medium severity), indicating a moderate risk with network attack vector, low complexity, no privileges required, and user interaction needed.
Mitigation Recommendations
No official patch or remediation information is provided in the vendor advisory or input data. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, users should consider avoiding use of affected versions or applying manual input sanitization to prevent injection of blank lines in code or pre elements.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-08-20T10:55:09.093Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6a8afb27acd9273b49f5f72b
Added to database: 08/23/2026, 13:52:39 UTC
Last enriched: 09/10/2026, 23:19:04 UTC
Last updated: 10/07/2026, 06:48:18 UTC
Views: 77
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.