CVE-2026-5389: justhtml before 1.13.0 XSS via code fence breakout

Published Aug 23, 2026
·
Updated

justhtml versions before 1.13.0 contain a cross-site scripting vulnerability in the tomarkdown() function when serializing attacker-controlled pre content. Attackers can place backticks inside sanitized pre elements to break out of fixed-length code fences, allowing raw HTML to execute when the generated Markdown is rendered by CommonMark or GFM-style renderers.

Affected Software

1 affected component
justhtml<1.13.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade justhtml to a version that resolves this vulnerability.

    Fixed in 1.13.0

Event History

Aug 23, 2026
CVE Published
via MITRE·01:34 PM
Data Sourced
via MITRE·01:34 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:16 PM
DescriptionSeverityWeakness
Aug 5, 58613
Event
via NVD·08:21 PM

Frequently Asked Questions

1

Who is exposed to this issue?

Applications using justhtml before 1.13.0 are exposed if they pass attacker-controlled content through to_markdown() and later render the generated Markdown with a CommonMark- or GFM-style renderer.

2

What must an attacker be able to do to exploit it?

An attacker needs to supply content that reaches a sanitized pre element. By placing backticks in that content, they can break out of the fixed-length code fence emitted during Markdown serialization and cause raw HTML to execute when the Markdown is rendered.

3

Is user interaction required?

Yes. The supplied vector indicates user interaction is required. The issue becomes relevant when someone views content produced from the affected Markdown serialization and rendered by a vulnerable Markdown rendering flow.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203