Prototype pollution in Jodit Editor - CVE-2026-55886

 

Prototype pollution in Jodit Editor - CVE-2026-55886

Published: July 27, 2026


Vulnerability identifier: #VU139550
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-55886
CWE-ID: CWE-1321
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary JavaScript code.

The vulnerability exists due to improper input validation in Jodit.modules.Helpers.set(). A remote attacker can pass specially crafted input to the application and perform prototype pollution, which can result in information disclosure or data manipulation.


Affected software

Jodit Editor

How to mitigate CVE-2026-55886

Install updates from vendor's website.

Jodit Editor - update to 4.12.26

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins