CVE-2026-58263
Deferred
Deferred - Pending Action
Mutation XSS in Jodit Editor via MathML and Style Tag Bypass
Vulnerability report for CVE-2026-58263, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-07-01
Last updated on: 2026-07-31
Assigner: GitHub, Inc.
Description
Description
Jodit Editor is a WYSIWYG editor with a built-in file browser & image editor. In versions prior to 4.12.28, the built-in clean-html sanitizer can be bypassed by a MathML/