Threat Advisory

SWC HTML Minifier Flaw Allows Script Element Breakout

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: Medium
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A medium-severity vulnerability, CVE-2026-72925 with a CVSS score of 6.1, exists in SWC HTML minifier, which may allow script element breakout when minifying embedded JSON. The flaw occurs because the minifier could convert escaped less-than signs into literal < characters, potentially transforming inert data into active markup. This allows an attacker to execute script in the origin of the generated page by crafting a payload that terminates the containing script element early via an escaped </script> sequence. Affected versions include those prior to 1.15.47-nightly-20260729.1 for @swc/html and before version 59.0.0 for swc_html_minifier, which could transform inert data into active markup if applications minify HTML containing attacker-controlled JSON data.

RECOMMENDATIONS:

  • We recommend you to update @swc/html to version 1.15.47-nightly-20260729.1.
  • We recommend you to update swc_html_minifier to version 59.0.0.

REFERENCES:

The following reports contain further technical details:[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A medium-severity vulnerability, CVE-2026-72925 with a CVSS score of 6.1, exists in SWC HTML minifier, which may allow script element breakout when minifying embedded JSON. The flaw occurs because the minifier could convert escaped less-than signs into literal < characters, potentially transforming inert data into active markup. This allows an attacker to execute script in the origin of the generated page by crafting a payload that terminates the containing script element early via an escaped </script> sequence. Affected versions include those prior to 1.15.47-nightly-20260729.1 for @swc/html and before version 59.0.0 for swc_html_minifier, which could transform inert data into active markup if applications minify HTML containing attacker-controlled JSON data.

RECOMMENDATIONS:

  • We recommend you to update @swc/html to version 1.15.47-nightly-20260729.1.
  • We recommend you to update swc_html_minifier to version 59.0.0.

REFERENCES:

The following reports contain further technical details:[emaillocker id="1283"]

[/emaillocker]
crossmenu