VYPR

allure-generator

by Qameta Software

CVEs (1)

  • CVE-2026-55847Jun 19, 2026
    risk 0.00cvss epss

    ## Summary The `ansi.js` Handlebars helper in allure-generator passes user-controlled `statusMessage` and `statusTrace` values from test result files through the `ansi-to-html` library and wraps the output in Handlebars `SafeString` without HTML escaping. Since `ansi-to-html`…