PT-2026-98421 · Lazy Html · Lazy Html
CVSS v4.0
2.3
Low
| Vector | AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
lazy html versions 0.1.0 through 0.1.12
Description
An issue exists where improper neutralization of input during web page generation allows mutation Cross-site Scripting (XSS). This occurs during a parse and serialize round-trip of attacker-supplied HTML. The functions
LazyHTML.to html/2 and LazyHTML.Tree.to html/2 determine whether to escape an element's text based solely on its tag name. Consequently, a style or script element within SVG or MathML foreign content is parsed with decoded character references but serialized as an HTML raw-text element, causing the text to be emitted unescaped. This allows encoded markup to close the element upon re-parsing and become active markup. Applications that parse untrusted HTML, filter the document or tree, and then serialize it for display are affected because the payload remains a plain text node that bypasses element or attribute filters.Recommendations
Update lazy html to version 0.1.13.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Lazy Html