← voltar
CVE-2026-25543

HtmlSanitizer has a bypass via template tag

CVSS 6.3 MEDIUMEPSS 0.2%CWE-116
HtmlSanitizer is a .NET library for cleaning HTML fragments and documents from constructs that can lead to XSS attacks. Prior to versions 9.0.892 and 9.1.893-beta, if the template tag is allowed, its contents are not sanitized. The template tag is a special tag that does not usually render its contents, unless the shadowrootmode attribute is set to open or closed. This issue has been patched in versions 9.0.892 and 9.1.893-beta.
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
Produtos afetados
mganss · HtmlSanitizer

Quer saber se a sua infraestrutura está exposta a isto?

Falar com a TrueHacking →