Threat Advisory

AngleSharp Flaw Lets Attackers Bypass HTML Integration Point

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: Medium
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

CVE-2026-54570 with a CVSS score of 6.9 is a CWE-80 mXSS vulnerability in AngleSharp, which does not correctly implement the HTML specification for treating MathML <annotation-xml> elements as HTML integration points, allowing injected markup to break out of attribute values on re-parse, and resulting in a DOM tree that differs from what a browser will build when given the same serialized output. This can be exploited via an annotation-xml element with encoding set to text/html, which is treated as an HTML integration point by browsers but not by AngleSharp, allowing injected markup to break out of attribute values on re-parse and potentially leading to mXSS attacks. The vulnerability affects versions prior to 1.5.0 of the AngleSharp package.

RECOMMENDATION:

We recommend you to update AngleSharp to version 1.5.0.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

CVE-2026-54570 with a CVSS score of 6.9 is a CWE-80 mXSS vulnerability in AngleSharp, which does not correctly implement the HTML specification for treating MathML <annotation-xml> elements as HTML integration points, allowing injected markup to break out of attribute values on re-parse, and resulting in a DOM tree that differs from what a browser will build when given the same serialized output. This can be exploited via an annotation-xml element with encoding set to text/html, which is treated as an HTML integration point by browsers but not by AngleSharp, allowing injected markup to break out of attribute values on re-parse and potentially leading to mXSS attacks. The vulnerability affects versions prior to 1.5.0 of the AngleSharp package.

RECOMMENDATION:

We recommend you to update AngleSharp to version 1.5.0.[emaillocker id="1283"]

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu