VYPR

hackage package

hackage-server

pkg:hackage/hackage-server

Vulnerabilities (3)

  • CVE-2026-40472CriApr 23, 2026
    affected >= 0.1

    In hackage-server, user-controlled metadata from .cabal files are rendered into HTML href attributes without proper sanitization, enabling stored Cross-Site Scripting (XSS) attacks.

  • CVE-2026-40471CriApr 23, 2026
    affected >= 0.1

    hackage-server lacked Cross-Site Request Forgery (CSRF) protection across its endpoints. Scripts on foreign sites could trigger requests to hackage server, possibly abusing latent credentials to upload packages or perform other administrative actions. Some unauthenticated actions

  • CVE-2026-40470CriApr 23, 2026
    affected >= 0.1, < 0.6fixed 0.6

    A critical XSS vulnerability affected hackage-server and hackage.haskell.org. HTML and JavaScript files provided in source packages or via the documentation upload facility were served as-is on the main hackage.haskell.org domain. As a consequence, when a user with latent HTTP