Vulnerability library
Security checkJuly 31, 2026

Jodit has incomplete javascript: scheme normalization in sanitizeHTMLElement href check that allows link XSS

Understand the exposure, see the recommended fix, and check whether your own website has related weaknesses.

Medium severitynpmjodit

Check your website

Find this and other vulnerabilities with a free scan.

Your scan runs on your computer. No account required.

Description

jodit’s sanitizeHTMLElement neutralizes a javascript: href using a bare href.trim().indexOf('javascript') === 0 check. This omits the normalization jodit applies to every other URL attribute: isDangerousUrl strips control bytes with value.replace(/[\u0000-\u0020]+/g, '') and lowercases the value before testing the scheme.

Recommendation

Update the jodit package to the latest compatible version. Followings are version details:

  • Affected version(s): <= 4.12.30
  • Patched version(s): 4.12.31

References

Could your website be exposed too?

SmartScanner can check your website for Jodit has incomplete javascript: scheme normalization in sanitizeHTMLElement href check that allows link XSS and gives you actionable findings to investigate.

Start a free scan

Related Issues

See something that needs correcting? Let us knowUpdated July 31, 2026