THREAT OPS › Threat News › [GHSA] GHSA-rxcw-mc6f-6hr3 (high) — Jodit Editor: Mutation XSS in jodit clean-html via a MathML/style rawtext carrier
[GHSA] GHSA-rxcw-mc6f-6hr3 (high) — Jodit Editor: Mutation XSS in jodit clean-html via a MathML/style rawtext carrier
GHSA-rxcw-mc6f-6hr3 Severity: high CVE: CVE-2026-58263
Jodit Editor: Mutation XSS in jodit clean-html via a MathML/style rawtext carrier
### Summary jodit's built-in `clean-html` sanitizer can be bypassed by a MathML/`<style>` carrier that hides a dangerous element from the sanitizer's element walk, so a no-interaction event handler survives into the editor value. When an application supplies at
Indicators of compromise
- CVE-2026-58263cve
- CVE-2023-42399cve
- CVE-2022-23461cve
Original source: https://github.com/advisories/GHSA-rxcw-mc6f-6hr3