CVE-2026-58263
Deferred Deferred - Pending Action

Mutation XSS in Jodit Editor via MathML and Style Tag Bypass

Vulnerability report for CVE-2026-58263, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-01

Last updated on: 2026-07-31

Assigner: GitHub, Inc.

Description

Jodit Editor is a WYSIWYG editor with a built-in file browser & image editor. In versions prior to 4.12.28, the built-in clean-html sanitizer can be bypassed by a MathML/