critical
CVE-2026-5388
justhtml URL sanitization and HTML serialization bypasses
- Severity
- critical
- Affected product
- justhtml
- Affected versions
- justhtml < 1.15.0
- Fixed in
- justhtml 1.15.0
- Added to NewScan
- 2026-08-23
- Detected by
- NewScan — free, self-hosted
How NewScan reports it
COMPONENT VERSION RANGE
NewScan fingerprints justhtml from its response and reports this CVE when the detected version falls inside the affected range below.
Version-match only: the existing requirements.txt parser supplies the exact justhtml pin. The affected helpers process attacker-controlled HTML, URLs, and Markdown, so active payloads are not submitted to a customer application.
References
Scan for this yourself — local, in-band scanning is free.
Get NewScan (FREE) →