PT-2026-94338 · Pypi · Ansi2Html

·

CVE-2026-92973

·

Published

2026-09-17

·

Updated

2026-09-25

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions ansi2html versions 1.7.0a0 through 1.9.3
Description An issue exists in the handling of OSC 8 hyperlinks where URL targets are not properly validated or escaped. This allows attackers who can control ANSI text input to inject javascript: schemes or terminate href attributes, leading to the execution of arbitrary scripts in the context of pages that display the converted output.
Recommendations Update to version 1.9.5 or later.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-92973
OPENSUSE-SU-2026:11815-1

Affected Products

Ansi2Html