๐Ÿ” CVE Alert

CVE-2026-92973

MEDIUM 6.1

ansi2html 1.7.0a0 through 1.9.3 Cross-Site Scripting via OSC 8

CVSS Score
6.1
EPSS Score
0.0%
EPSS Percentile
0th

ansi2html versions 1.7.0a0 through 1.9.3 contain a cross-site scripting vulnerability in OSC 8 hyperlink handling that fails to validate or escape URL targets. Attackers controlling ANSI text input can inject javascript: schemes or terminate href attributes to execute arbitrary scripts in the context of pages displaying converted output.

CWE CWE-79
Vendor pycontribs
Product ansi2html
Published Sep 17, 2026
Stay Ahead of the Next One

Get instant alerts for pycontribs ansi2html

Be the first to know when new medium vulnerabilities affecting pycontribs ansi2html are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None

Affected Versions

pycontribs / ansi2html
1.7.0a0 < 1.9.4

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/pycontribs/ansi2html/commit/89d1c231c60ac52005f3b21bbba551c786c554fc github.com: https://github.com/pycontribs/ansi2html/blob/v1.9.3/src/ansi2html/converter.py#L345-L349 github.com: https://github.com/pycontribs/ansi2html vulncheck.com: https://www.vulncheck.com/advisories/ansi2html-1.7-0a0-through-1.9.3-cross-site-scripting-via-osc-8

Credits

Arkadiusz Kozdra