THREAT OPS › Threat News › [GHSA] GHSA-45qg-252v-3f7p (medium) — Jodit has cross-site scripting (XSS) via <script> nested in SVG that bypasses clean-html sanitization
[GHSA] GHSA-45qg-252v-3f7p (medium) — Jodit has cross-site scripting (XSS) via <script> nested in SVG that bypasses clean-html sanitization
GHSA-45qg-252v-3f7p Severity: medium CVE: CVE-2026-65841
Jodit has cross-site scripting (XSS) via <script> nested in SVG that bypasses clean-html sanitization
A `<script>` element placed directly inside an `<svg>` (or MathML) container was not removed by Jodit's clean-html sanitizer.
The deny/allow tag filter compared `node.nodeName` against an upper-cased tag hash, but foreign (SVG/MathML) ele
MITRE ATT&CK techniques
- JavaScriptT1059.007
Indicators of compromise
- CVE-2026-65841cve
Original source: https://github.com/advisories/GHSA-45qg-252v-3f7p