HIGH 7.2 GitHub
CVE-2026-58263
Jodit Editor: Mutation XSS in jodit clean-html via a MathML/style rawtext carrier
### Summary
jodit's built-in `clean-html` sanitizer can be bypassed by a MathML/`<style>` carrier that hides a dangerous element from the sanitizer's element walk, so a no-interaction event handler survives into the editor value. When an application supplies attacker-influenced HTML to the editor's value-set or insertion paths, the sanitized output still contains a live `<img ... onload=...>` (or another non-`onerror` handler such as `onfocus`). A consumer that renders that output (`element.inne
Affected Products
- npm/jodit < 4.12.28
References
- https://github.com/advisories/GHSA-rxcw-mc6f-6hr3
- https://github.com/xdan/jodit/security/advisories/GHSA-rxcw-mc6f-6hr3
- https://nvd.nist.gov/vuln/detail/CVE-2026-58263
- https://github.com/xdan/jodit/commit/0ebb61692cbe84f9abf10ac76dd594dbb6343b90
This high severity vulnerability with a CVSS score of 7.2 was published on 2026-07-31 via GitHub. Affected: npm/jodit < 4.12.28.
vulnfeed aggregates 9166 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.