THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-45qg-252v-3f7p (medium) — Jodit has cross-site scripting (XSS) via <script> nested in SVG that bypasses clean-html sanitization

[GHSA] GHSA-45qg-252v-3f7p (medium) — Jodit has cross-site scripting (XSS) via <script> nested in SVG that bypasses clean-html sanitization

medgithub_advisoriesPublished 2026-07-31

GHSA-45qg-252v-3f7p Severity: medium CVE: CVE-2026-65841

Jodit has cross-site scripting (XSS) via <script> nested in SVG that bypasses clean-html sanitization

A `<script>` element placed directly inside an `<svg>` (or MathML) container was not removed by Jodit's clean-html sanitizer.

The deny/allow tag filter compared `node.nodeName` against an upper-cased tag hash, but foreign (SVG/MathML) ele

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-45qg-252v-3f7p