Highlight.js is a syntax-highlighting library deployed in documentation systems, technical blogs, and code-sharing platforms, where it processes untrusted input from user-supplied code snippets. The library's observed exposure centers on modification of assumed-immutable data, a weakness class reflecting the parsing and state-management challenges inherent to language-recognition libraries that must safely transform and display arbitrary source code. Current severity, exploitation, and exposure figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Highlightjs over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-26237HIGH Highlight.js is a syntax highlighter written in JavaScript. Highlight.js versions before 9.18.2 and 10.1.2 are vulnerable to Prototype Pollution. A malicious HTML code block can be | Nov 24, 2020 | 8.7 | 27 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Highlightjs.
Media articles that mention a CVE ID that affects a product developed by Highlightjs — matched by CVE ID, not by vendor name.