SWC HTML minifier may allow script element breakout when minifying embedded JSON
13Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 6.1epss 0.2%
probabilidad de explotación
0.2%top 91% de las CVE
explotación observada
noninguna fuente lo reporta
SWC is a TypeScript / JavaScript compiler written in Rust. Prior to @swc/html 1.15.47-nightly-20260729.1 and swc_html_minifier 59.0.0, the minifyJson processing in crates/swc_html_minifier/src/lib.rs parsed and serialized attacker-controlled JSON in application/json and application/ld+json script elements without the escape_json_for_html_script behavior to re-escape less-than signs, allowing a closing script sequence to terminate the element early and execute script in the generated page's origin. This issue is fixed in @swc/html 1.15.47-nightly-20260729.1 and swc_html_minifier 59.0.0.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Referencias
https://github.com/swc-project/swc/commit/e1877b44bdac8abc9fd51e984d584f40f6999832https://github.com/swc-project/swc/pull/12080https://github.com/swc-project/swc/releases/tag/v1.15.47https://github.com/swc-project/swc/releases/tag/v1.15.47-nightly-20260729.1https://github.com/swc-project/swc/security/advisories/GHSA-5qr2-v392-m9g8