VDB
CVE-2026-92973
CVE-2026-92973
PUBLISHED
CVSS 5.3 MEDIUM
Reported by VulnCheck · Published September 17, 2026
ansi2html versions 1.7.0a0 through 1.9.3 contain a cross-site scripting vulnerability in OSC 8 hyperlink handling that fails to validate or escape URL targets. Attackers controlling ANSI text input can inject javascript: schemes or terminate href attributes to execute arbitrary scripts in the context of pages displaying converted output.
Risk Scores
CVSS 4.0
5.3
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| pycontribs | ansi2html | 1.7.0a0 |
| pycontribs | ansi2html | 1.7.0a0 |
| ansi2html_project | ansi2html | 1.7.0a0 |
Timeline
- Sep 17, 2026 Coalition ESS Score
- Sep 17, 2026 CVE Published
- Sep 17, 2026 CVE Updated
- Sep 18, 2026 EPSS Score
References
- Patch Commit patch
- technical-description
- product
- VulnCheck Advisory: ansi2html 1.7.0a0 through 1.9.3 Cross-Site Scripting via OSC 8 third-party-advisory