Medium severity6.1NVD Advisory· Published Sep 17, 2026· Updated Sep 17, 2026
CVE-2026-92973
CVE-2026-92973
Description
ansi2html versions 1.7.0a0 through 1.9.3 contain a cross-site scripting vulnerability in OSC 8 hyperlink handling that fails to validate or escape URL targets. Attackers controlling ANSI text input can inject javascript: schemes or terminate href attributes to execute arbitrary scripts in the context of pages displaying converted output.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: 1.7.0a0 - 1.9.3
Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.