© 2025-2026 PySpect
First version without a known vulnerability: 1.22.0
justhtml: to_markdown() code-span blank-line breakout enables XSS
Fixed in: 1.22.0
justhtml introduces denial-of-service hardening
Fixed in: 1.18.0
justhtml has sanitization bypass in custom policies and programmatic DOM
Fixed in: 1.17.0
Multiple security fixes in justhtml
Fixed in: 1.16.0
justhtml includes multiple security fixes
Fixed in: 1.15.0
justhtml: Mutation XSS with custom foreign-namespace sanitization policies
Fixed in: 1.14.0
JustHTML is vulnerable to XSS via code fence breakout in <pre> content
Fixed in: 1.13.0
JustHTML has a Sanitizer Bypass (in Markdown)
Fixed in: 1.12.0
JustHTML Affected by Mutation XSS via Literal Text Serialization in Raw Text Elements (style/script)
Fixed in: 1.12.0
Uncontrolled recursion DoS in JustHTML() via deeply nested HTML
Fixed in: 1.10.0