Vulnerabilities/

Jodit Editor: Mutation XSS in jodit clean-html via a MathML/style rawtext carrier

Severity:
High

Description

jodit’s built-in clean-html sanitizer can be bypassed by a MathML/<style> carrier that hides a dangerous element from the sanitizer’s element walk, so a no-interaction event handler survives into the editor value.

Recommendation

Update the jodit package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
jodit
Anything's wrong? Let us know Last updated on July 31, 2026