CVE-2026-77088: justhtml 0.9.0 through 1.21.0 Cross-Site Scripting via code-span

Published Aug 23, 2026
·
Updated

justhtml versions 0.9.0 through 1.21.0 contain a cross-site scripting vulnerability in tomarkdown() where inline code spans fail to account for blank lines as block boundaries. Attackers can inject blank lines into code or pre element text to break the inline span, causing sanitized HTML to be emitted unescaped and re-parsed as live Markdown by compliant renderers.

Affected Software

1 affected component
justhtml>=0.9.0<=1.21.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade justhtml to a version that resolves this vulnerability.

    Fixed in 1.21.0

Event History

Aug 23, 2026
CVE Published
via MITRE·01:34 PM
Data Sourced
via MITRE·01:34 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:16 PM
DescriptionSeverityWeakness
Aug 5, 58613
Event
via NVD·08:23 PM

Frequently Asked Questions

1

Who is exposed to this issue?

Applications using justhtml versions 0.9.0 through 1.21.0 are exposed when they call to_markdown() on attacker-controlled or otherwise untrusted HTML and the resulting Markdown is rendered by a compliant renderer.

2

What does an attacker need to exploit it?

An attacker needs to be able to place blank lines within text in code or pre elements that will be processed by to_markdown(). The malformed inline code span can then cause sanitized HTML to be emitted unescaped and interpreted as live Markdown.

3

How can I determine whether my application is affected?

Check whether your application uses a justhtml version from 0.9.0 through 1.21.0 and converts HTML to Markdown with to_markdown(). Risk is present if untrusted input can reach code or pre element text and the generated Markdown is subsequently rendered.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203