Critical severity9.9NVD Advisory· Published Apr 23, 2026· Updated Apr 24, 2026
CVE-2026-40472
CVE-2026-40472
Description
In hackage-server, user-controlled metadata from .cabal files are rendered into HTML href attributes without proper sanitization, enabling stored Cross-Site Scripting (XSS) attacks.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.