LOW
dashbitco
CVE published 2026-09-25
CVE-2026-92106
A Cross-site Scripting (XSS) vulnerability exists in the lazy_html library, affecting versions from 0.1.0 before 0.1.13. The issue arises from the improper neutralization of input during web page generation, allowing for mutation XSS via a parse and serialize round-trip of attacker-supplied HTML. Specifically, the library fails to properly escape text within style or script elements inside SVG or MathML f [truncated]