CVEReports
CVEReports

Automated vulnerability intelligence platform. Comprehensive reports for high-severity CVEs generated by AI.

Product

  • Home
  • Sitemap
  • RSS Feed

Company

  • About
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CVEReports. All rights reserved.

Made with love by Amit Schendel & Alon Barad



CVE-2026-58263

CVE-2026-58263: Mutation Cross-Site Scripting (mXSS) in Jodit Editor clean-html Sanitizer

Amit Schendel
Amit Schendel
Senior Security Researcher

Aug 1, 2026·6 min read·30 visits

Executive Summary (TL;DR)

Unauthenticated remote mutation cross-site scripting (mXSS) in Jodit Editor < 4.12.28 allows attackers to bypass HTML sanitization and execute arbitrary JavaScript by leveraging parser differentials between the inert sanitization sandbox and the live editor DOM.

CVE-2026-58263 is a high-severity Mutation Cross-Site Scripting (mXSS) vulnerability affecting Jodit Editor prior to version 4.12.28. The flaw exists in Jodit's built-in clean-html sanitizer plugin, which fails to securely parse and sanitize nested elements containing foreign namespaces like MathML and SVG. Attackers can bypass sanitization by smuggling malicious payload elements inside rawtext container tags like style inside a MathML node, leading to DOM mutation and unauthenticated arbitrary script execution in the context of the user's browser session.

Vulnerability Overview

Jodit Editor is a client-side, browser-based WYSIWYG editor containing advanced text processing, image, and file management functions. To protect against malicious cross-site scripting vectors, the application exposes a built-in input sanitization engine via the clean-html plugin. This plugin processes untrusted HTML inputs, aiming to neutralize malicious tags and properties prior to rendering.\n\nThe attack surface exists on the client-side parsing interface where rich text is processed. By leveraging the discrepancy in how different browser engines handle parsing state transitions, attackers can exploit CVE-2026-58263 to bypass the sanitization process entirely. The vulnerability belongs to the Mutation Cross-Site Scripting class, specifically involving the abuse of foreign namespaces like MathML and SVG combined with HTML elements that transition the parsing engine's parsing rules.\n\nThe consequences of this vulnerability are severe. Successful exploitation results in the execution of arbitrary JavaScript code within the victim's browser context. This execution is achieved with zero user interaction upon the rendering of the poisoned HTML within the Jodit Editor window.

Root Cause Analysis

Mutation Cross-Site Scripting relies on a parsing differential between the inert DOM structure utilized by a sanitizer and the live DOM structure initialized by the browser when displaying content. During the sanitization phase, Jodit places the raw HTML inside an inert container, such as a template element or an offline document fragment, to prevent execution. The sanitizer then walks the resulting DOM tree to inspect and purge non-whitelisted tags or event attributes.\n\nIn the vulnerable versions of Jodit Editor, the clean-html sanitizer does not account for the structural mutation rules dictated by the HTML5 parsing specification when nesting HTML elements inside foreign namespaces. When the browser parser encounters a math or svg tag, it transitions into a foreign content parsing mode. In this mode, tags like style are not treated as standard HTML RAWTEXT elements, but are parsed according to MathML parsing behaviors.\n\nBy nesting a table and rawtext elements such as style within a MathML element like mtext, the attacker constructs a payload that changes its structure during parsing and serialization. In the inert sandbox, the nested img node is viewed as harmless raw text inside the style tag. Jodit's DOM walker fails to detect the element because it exists purely as a text node at that stage.\n\nDuring serialization, Jodit extracts the content as a string using element.innerHTML. When the host application parses this serialized string a second time to render it in the live DOM, the HTML5 foster-parenting rules trigger. The browser parser detects the invalid nesting of a table structure within the MathML namespace, prematurely exits the MathML context, and hoists the nested nodes. The previously inert text inside the style block is parsed as a real HTML image tag, restoring its event attributes and executing the payload.\n\nmermaid\ngraph LR\n A["Poisoned Payload Input"] --> B["Inert DOM Parsing"]\n B --> C["Sanitization Walk"]\n C --> D["HTML String Serialization"]\n D --> E["Live DOM Insertion"]\n E --> F["Foster-Parenting Breakout"]\n F --> G["Active XSS Execution"]\n

Code Analysis

To understand the mechanical breakdown of this vulnerability, we must examine the implementation of Jodit's sanitizer. The vulnerable component failed to validate elements nested within foreign namespaces before traversing the tree for event attributes. This omission allowed structural elements to bypass sanitization in an inert text state.\n\nThe fix introduced in version 4.12.28 implements a proactive detection pass before the main tree walk. It identifies smuggled HTML elements that are incorrectly nested within foreign content contexts. The following typescript snippet highlights the validation logic implemented in the patch:\n\ntypescript\nconst HTML_NAMESPACE = 'http://www.w3.org/1999/xhtml';\n\nconst HTML_INTEGRATION_POINTS = new Set([\n\t'foreignobject',\n\t'annotation-xml',\n\t'desc',\n\t'title'\n]);\n\nfunction isSmuggledForeignHtml(elm: Element): boolean {\n\tif (elm.namespaceURI !== HTML_NAMESPACE || elm.closest('math,svg') === null) {\n\t\treturn false;\n\t}\n\n\tfor (let parent = elm.parentElement; parent; parent = parent.parentElement) {\n\t\tconst name = parent.nodeName.toLowerCase();\n\n\t\tif (name === 'math' || name === 'svg') {\n\t\t\tbreak;\n\t\t}\n\n\t\tif (HTML_INTEGRATION_POINTS.has(name)) {\n\t\t\treturn false;\n\t\t}\n\t}\n\n\treturn true;\n}\n\n\nBefore executing the standard sanitization walk, the patch queries all child elements of math and svg containers. Any element determined to be smuggled foreign HTML is removed safely from the tree. This prevents the browser's live parser from encountering the nested table structure that triggers foster-parenting during serialization and subsequent rendering.

Exploitation Methodology

Exploitation of CVE-2026-58263 does not require authentication or complex configurations. The attacker must only possess the ability to submit structured HTML content to an endpoint or an interface rendered within the Jodit WYSIWYG editor.\n\nThe core of the payload relies on the browser's implementation of error-recovery algorithms. By structuring the markup with math, mtext, table, mglyph, and style tags, the parser's state is manipulated. Inside the style container, the attacker places a raw image tag with inline execution attributes.\n\nhtml\n<math>\n <mtext>\n <table>\n <mglyph>\n <style>\n <img src='data:image/gif;base64,R0lGODlhAQABAIAAAAAAAP///yH5BAEAAAAALAAAAAABAAEAAAIBRAA7' onload='alert(document.domain)' onerror='alert(document.domain)' onfocus='alert(document.domain)' autofocus tabindex='0'>\n </style>\n </mglyph>\n </table>\n </mtext>\n</math>\n\n\nWhen this input is serialized, the output string remains structurally identical. However, when the live browser engine executes the assignment to innerHTML, the nesting rules are evaluated. The presence of the table element forces the parser to eject from the MathML context and process the downstream tokens as standard HTML. The img tag is hoisted out of the style block and parsed into a live node, immediately triggering the onload, onerror, or onfocus attributes.

Impact Assessment

The impact of this vulnerability is classified as high, carrying a CVSS base score of 7.2. Since the payload executes inside the client-side browser environment, the immediate consequence is the arbitrary execution of JavaScript in the context of the victim's session. This allows for session hijacking, local storage data extraction, and unauthorized action execution on behalf of the user.\n\nThe scope of the vulnerability is changed, reflecting that compromise of the editor's sandboxed parsing environment leads directly to compromise of the surrounding web application. This vector bypasses traditional client-side mitigations like basic HTML sanitizers and simple input sanitization filters.\n\nAdditionally, although the EPSS score indicates low active exploitation in the wild, the publication of the proof of concept in unit tests lowers the barrier to entry for constructing functional exploits. Applications using Jodit to display user-generated rich text are at direct risk of client-side compromise.

Remediation and Mitigation Guidance

Remediation of CVE-2026-58263 requires updating the Jodit Editor deployment to version 4.12.28 or above. This version contains the isSmuggledForeignHtml check inside the safeHTML module, which stops the serialization of hazardous nested namespaces.\n\nWhere updating is not immediately feasible, organizations must employ server-side defenses. A robust HTML sanitizer such as DOMPurify should be executed on the server before rich text content is stored in databases or rendered back to other users. Client-side editors should not be treated as a single point of defense.\n\nImplementing a strict Content Security Policy (CSP) provides an additional layer of security. By enforcing policies such as restricting inline script execution and disabling the evaluation of dynamic code, the execution of injected mXSS payloads can be successfully blocked even if the sanitizer is bypassed.

Official Patches

xdanOfficial patch commit fixing mXSS in the safeHTML helper
xdanRelease tag 4.12.28

Fix Analysis (1)

Technical Appendix

CVSS Score
7.2/ 10
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
EPSS Probability
0.18%
Top 92% most exploited

Affected Systems

Jodit Editor client-side application

Affected Versions Detail

Product
Affected Versions
Fixed Version
Jodit Editor
xdan
< 4.12.284.12.28
AttributeDetail
CWE IDCWE-79
Attack VectorNetwork (Unauthenticated)
CVSS v3.17.2 (High)
EPSS Score0.00179
ImpactMutation XSS (Client-Side Code Execution)
Exploit StatusPoC (In Unit Tests)
CISA KEV StatusNot Listed

MITRE ATT&CK Mapping

T1189Drive-by Compromise
Initial Access
T1185Browser Session Hijacking
Collection
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The software does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Known Exploits & Detection

GitHub Unit TestsProof of concept payload integrated directly into the test suite of Jodit Editor.

Vulnerability Timeline

Fix commit merged into Jodit master branch
2026-06-22
Security advisory published and CVE assigned
2026-07-01

References & Sources

  • [1]GitHub Security Advisory GHSA-rxcw-mc6f-6hr3
  • [2]NVD - CVE-2026-58263
  • [3]CVE Record - CVE-2026-58263

Attack Flow Diagram

Press enter or space to select a node. You can then use the arrow keys to move the node around. Press delete to remove it and escape to cancel.
Press enter or space to select an edge. You can then press delete to remove it or escape to cancel.

More Reports

•30 minutes ago•GHSA-FPRF-R6RV-XG99
6.5

GHSA-FPRF-R6RV-XG99: Cross-Tenant Task Position Recalculation in Vikunja

A cross-tenant boundary breach vulnerability in Vikunja allows an authenticated user to trigger global task position recalculations across all tenant instances by creating a saved filter with an empty filter string payload.

Amit Schendel
Amit Schendel
3 views•4 min read
•about 1 hour ago•GHSA-HJX8-QV73-F7CM
6.5

GHSA-HJX8-QV73-F7CM: Incomplete Access Revocation Leading to Webhook Data Exfiltration in Vikunja

An access revocation flaw in Vikunja allows removed collaborators to retain outbound webhooks and link shares created prior to revocation, enabling persistent exfiltration of sensitive task data.

Alon Barad
Alon Barad
4 views•5 min read
•about 2 hours ago•GHSA-PJR3-86V4-5P7W
5.4

GHSA-PJR3-86V4-5P7W: Broken Access Control via MAX Aggregation in Vikunja Subtree Permissions

Vikunja v2.6.0 contains a permission inheritance regression in pkg/models/project_access.go where explicit down-restrictions on sub-projects are overridden by higher parent project permissions due to MAX aggregation across project tree nodes.

Alon Barad
Alon Barad
4 views•6 min read
•about 3 hours ago•GHSA-FMMF-XQ98-G327
5.3

GHSA-fmmf-xq98-g327: Write-Level Project Members Can Delete Admin-Tier Link Shares in Vikunja

An authorization bypass vulnerability in Vikunja's link share deletion handlers allows project members with Write privileges to delete Admin-tier link shares. The handler passes an unpopulated struct to the authorization check, causing the permission evaluation to fall back to default Write permissions instead of requiring Admin privileges.

Alon Barad
Alon Barad
7 views•5 min read
•about 5 hours ago•GHSA-M687-P538-R5HP
7.2

GHSA-m687-p538-r5hp: Permissive Localhost CORS Policy Leads to Account Takeover in Vikunja

Vikunja versions 2.2.0 through 2.6.0 contain a Cross-Origin Resource Sharing (CORS) misconfiguration flaw in `code.vikunja.io/api`. Default configurations permit wildcard origins for localhost (`http://127.0.0.1:*` and `http://localhost:*`) with credentialed requests (`Access-Control-Allow-Credentials: true`). Because configuring a public service URL appends to this default list rather than overriding it, production environments inadvertently trust all local origins. A local page or application on a user's machine can execute a credentialed cross-origin request to the token refresh endpoint, extract the returned JWT access token, and achieve complete account takeover.

Alon Barad
Alon Barad
8 views•5 min read
•about 11 hours ago•GHSA-JQ7H-WRVP-3RGX
7.5

GHSA-JQ7H-WRVP-3RGX: Insufficient Session Invalidation in pyLoad Core REST API

An insufficient session invalidation vulnerability exists in pyLoad (pyload-ng) versions 0.5.0b3.dev98 through 0.5.0b3.dev101. When administrative actions like privilege revocation or password changes are executed via the public REST API, active user sessions on disk are not updated or invalidated. Consequently, affected sessions remain fully authenticated with stale permissions for up to 31 days.

Amit Schendel
Amit Schendel
8 views•4 min read