Vulnerability Description
Jodit Editor is a WYSIWYG editor with a built-in file browser & image editor. Prior to 4.13.6, Jodit's clean-html denyTags filter does not normalize foreign SVG or MathML script node names, allowing a script element nested directly in SVG or MathML to remain in editor.value and execute when content is loaded. This issue is fixed in version 4.13.6.
Related Weaknesses (CWE)
References
- https://github.com/xdan/jodit/commit/49a31f451f6b686f5610022a1d4406ee85138dc5
- https://github.com/xdan/jodit/releases/tag/4.13.6
- https://github.com/xdan/jodit/security/advisories/GHSA-45qg-252v-3f7p
- https://github.com/xdan/jodit/security/advisories/GHSA-45qg-252v-3f7p
FAQ
What is CVE-2026-65841?
CVE-2026-65841 is a documented vulnerability. Jodit Editor is a WYSIWYG editor with a built-in file browser & image editor. Prior to 4.13.6, Jodit's clean-html denyTags filter does not normalize foreign SVG or MathML script node names, allowing a...
How severe is CVE-2026-65841?
CVSS scoring is not yet available for CVE-2026-65841. Check NVD for updates.
Is there a patch for CVE-2026-65841?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.