ansi2html versions 1.7.0a0 through 1.9.3 contain a cross-site scripting vulnerability in OSC 8 hyperlink handling that fails to validate or escape URL targets. Attackers controlling ANSI text input can inject javascript: schemes or terminate href attributes to execute arbitrary scripts in the context of pages displaying converted output.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 17 Sep 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ansi2html versions 1.7.0a0 through 1.9.3 contain a cross-site scripting vulnerability in OSC 8 hyperlink handling that fails to validate or escape URL targets. Attackers controlling ANSI text input can inject javascript: schemes or terminate href attributes to execute arbitrary scripts in the context of pages displaying converted output. | |
| Title | ansi2html 1.7.0a0 through 1.9.3 Cross-Site Scripting via OSC 8 | |
| First Time appeared |
Ansi2html Project
Ansi2html Project ansi2html |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:ansi2html_project:ansi2html:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Ansi2html Project
Ansi2html Project ansi2html |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-17T15:38:41.098Z
Reserved: 2026-09-17T13:24:03.383Z
Link: CVE-2026-92973
No data.
Status : Received
Published: 2026-09-17T14:18:03.507
Modified: 2026-09-17T14:18:03.507
Link: CVE-2026-92973
No data.
OpenCVE Enrichment
No data.
Weaknesses