Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-92106— lazy_html serializes SVG and MathML style and script text unescaped, allowing mutation XSS

Quick assessment

Affected
dashbitco lazy_html
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 dashbitco 库的 模块中存在一种“网页生成期间输入中和不当”(即跨站脚本攻击,XSS)漏洞,攻击者可以通过对提供的 HTML 进行解析与序列化往返操作,实现变异型 XSS。 和 仅根据元素的标签名来决定是否转义其文本内容。当 SVG 或 MathML 外部内容(foreign content)中嵌入 或 元素时,这些元素在解析阶段会将字符引用(如 )解码,但在序列化时却被当作 HTML 原始文本元素处理,导致其内部文本未被转义地直接输出。例如,在 内部包含编码后的标记如 ,在重新解析时,该 会闭合当前的

CVSS 2.3 · Low EPSS 0.39% · P31

Affected Version Matrix 2

VendorProduct Version RangeStatus
dashbitco lazy_html 0.1.0< 0.1.13 affected
1dee15746c024916b3110af8b168c2f3b3065fbd< f32c7fd6223225b68bc8691c78b6d4a77972f1d5 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-92106

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
lazy_html serializes SVG and MathML style and script text unescaped, allowing mutation XSS
Source: CVE Program / CVE List V5
Vulnerability Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in dashbitco lazy_html allows mutation XSS via a parse and serialize round-trip of attacker-supplied HTML. LazyHTML.to_html/2 and LazyHTML.Tree.to_html/2 decide whether to escape an element's text from its tag name alone. A style or script element inside SVG or MathML foreign content is parsed with character references decoded, but is serialized as an HTML raw-text element, so its text is emitted unescaped. Encoded markup such as &lt;/style&gt;&lt;img src=x onerror=...&gt; inside <svg><style> therefore closes the element on re-parse and becomes live markup. Applications that parse untrusted HTML with lazy_html, filter the document or tree, and serialize it for display are affected, since the payload is a plain text node that no element or attribute filter sees. This issue affects lazy_html: from 0.1.0 before 0.1.13.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
dashbitco lazy_html 0.1.0 ~ 0.1.13 cpe:2.3:a:dashbitco:lazy_html:*:*:*:*:*:*:*:*
dashbitco lazy_html 1dee15746c024916b3110af8b168c2f3b3065fbd ~ f32c7fd6223225b68bc8691c78b6d4a77972f1d5 cpe:2.3:a:dashbitco:lazy_html:*:*:*:*:*:*:*:*

II. Public POCs for CVE-2026-92106

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-92106

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-92106 (1)

Vendor Advisories for CVE-2026-92106 (3)

IV. Related Vulnerabilities

V. Comments for CVE-2026-92106

No comments yet


Leave a comment