jodit is vulnerable to Cross-Site Scripting (XSS)
72
High Risk
The HTML sanitizer in jodit walks parsed content as elements, but markup smuggled as style rawtext inside a MathML or SVG foreign-content carrier is not an element during that walk and escapes cleaning. A later serialize-and-reparse hoists the hidden markup, such as an img carrying an on* handler, into a live HTML node with its event handler intact. An application that re-renders the editor value then runs attacker-supplied script with no user interaction, producing stored cross-site scripting in the default configuration. The fix removes HTML-namespace elements the parser placed inside math or svg outside integration points before the walk, including nested carriers.
You are affected if you are using a version that falls within the vulnerable range and your application re-renders editor content as HTML.
jodit is vulnerable to Cross-Site Scripting (XSS) in versions 1.0.1 - 4.12.27.
Upgrade the jodit library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant