A medium-severity vulnerability, CVE-2026-72925 with a CVSS score of 6.1, exists in SWC HTML minifier, which may allow script element breakout when minifying embedded JSON. The flaw occurs because the minifier could convert escaped less-than signs into literal < characters, potentially transforming inert data into active markup. This allows an attacker to execute script in the origin of the generated page by crafting a payload that terminates the containing script element early via an escaped </script> sequence. Affected versions include those prior to 1.15.47-nightly-20260729.1 for @swc/html and before version 59.0.0 for swc_html_minifier, which could transform inert data into active markup if applications minify HTML containing attacker-controlled JSON data.
The following reports contain further technical details:[/subscribe_to_unlock_form]
A medium-severity vulnerability, CVE-2026-72925 with a CVSS score of 6.1, exists in SWC HTML minifier, which may allow script element breakout when minifying embedded JSON. The flaw occurs because the minifier could convert escaped less-than signs into literal < characters, potentially transforming inert data into active markup. This allows an attacker to execute script in the origin of the generated page by crafting a payload that terminates the containing script element early via an escaped </script> sequence. Affected versions include those prior to 1.15.47-nightly-20260729.1 for @swc/html and before version 59.0.0 for swc_html_minifier, which could transform inert data into active markup if applications minify HTML containing attacker-controlled JSON data.
The following reports contain further technical details:[emaillocker id="1283"]
[/emaillocker]