PatchSiren

AngleSharp CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM AngleSharp CVE published 2026-08-18

CVE-2026-54570

CVE-2026-54570 AngleSharp MathAnnotationXmlElement DOM Differential XSS. The AngleSharp library prior to version 1.5.0 has a vulnerability in MathAnnotationXmlElement. When the encoding attribute is set to text/html or application/xhtml+xml, it is not treated as an HTML integration point. This causes the Consume method in HtmlDomBuilder.cs to route tokens through foreign-content parsing instead of HTML pa [truncated]