PT-2026-98421 · Lazy Html · Lazy Html

·

CVE-2026-92106

·

Published

2026-09-25

·

Updated

2026-09-25

CVSS v4.0

2.3

Low

VectorAV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions lazy html versions 0.1.0 through 0.1.12
Description An issue exists where improper neutralization of input during web page generation allows mutation Cross-site Scripting (XSS). This occurs during a parse and serialize round-trip of attacker-supplied HTML. The functions LazyHTML.to html/2 and LazyHTML.Tree.to html/2 determine whether to escape an element's text based solely on its tag name. Consequently, a style or script element within SVG or MathML foreign content is parsed with decoded character references but serialized as an HTML raw-text element, causing the text to be emitted unescaped. This allows encoded markup to close the element upon re-parsing and become active markup. Applications that parse untrusted HTML, filter the document or tree, and then serialize it for display are affected because the payload remains a plain text node that bypasses element or attribute filters.
Recommendations Update lazy html to version 0.1.13.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-92106
GHSA-8RQP-V692-V82Q

Affected Products

Lazy Html