Prototype pollution in Jodit Editor - CVE-2026-54756

 

Prototype pollution in Jodit Editor - CVE-2026-54756

Published: July 27, 2026


Vulnerability identifier: #VU139517
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-54756
CWE-ID: CWE-1321
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary JavaScript code.

The vulnerability exists due to improper input validation within Jodit.configure(options) and the internal ConfigMerge, ConfigProto helpers. A remote attacker can pass specially crafted input to the application and perform prototype pollution, which can result in information disclosure or data manipulation.


Affected software

Jodit Editor

How to mitigate CVE-2026-54756

Install updates from vendor's website.

Jodit Editor - update to 4.12.18

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins