Pypi · Ansi2Html · CVE-2026-92973
**Name of the Vulnerable Software and Affected Versions**
ansi2html versions 1.7.0a0 through 1.9.3
**Description**
An issue exists in the handling of OSC 8 hyperlinks where URL targets are not properly validated or escaped. This allows attackers who can control ANSI text input to inject `javascript:` schemes or terminate `href` attributes, leading to the execution of arbitrary scripts in the context of pages that display the converted output.
**Recommendations**
Update to version 1.9.5 or later.