VYPR

lazy_html

by Dashbitco

CVEs (1)

  • CVE-2026-92106LowSep 25, 2026
    risk 0.08cvss —epss —

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in dashbitco lazy_html allows mutation XSS via a parse and serialize round-trip of attacker-supplied HTML. LazyHTML.to_html/2 and LazyHTML.Tree.to_html/2 decide whether to escape…