What is CVE-2026-65841?
CVE-2026-65841 is a vulnerability in Jodit Editor before version 4.13.6, where the clean-html denyTags filter fails to normalize foreign SVG or MathML script node names. This allows a script element nested in SVG/MathML to persist in editor.value and execute when the content is rendered.
Azərbaycanca: CVE-2026-65841, Jodit Editor-un 4.13.6 versiyasından əvvəlki versiyalarında aşkarlanan zəiflikdir. Təmizləmə filtrinin SVG/MathML daxilindəki script elementlərini normalaşdırmaması səbəbindən, xüsusi hazırlanmış məzmun redaktorda saxlanılır və icra oluna bilər.
Related CVEs
link basis: same weakness class CWE-79
FAQ1
How can the CVE-2026-65841 vulnerability in Jodit Editor be exploited?
The vulnerability occurs because the clean-html denyTags filter fails to normalize foreign SVG or MathML script node names. An attacker can inject specially crafted malicious content that bypasses the filter, persists in `editor.value`, and executes when the content is rendered.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.