Cross-site Scripting Vulnerability in Dashbitco LazyHTML Product
CVE-2026-92106

2.3LOW

Key Information:

Vendor

Dashbitco

Status
Vendor
CVE Published:
25 September 2026

What is CVE-2026-92106?

The vulnerability in Dashbitco's LazyHTML arises from improper handling of input during web page generation, specifically within SVG and MathML content. When an attacker supplies compromised HTML, the affected versions of LazyHTML fail to appropriately escape elements' text. This misconfiguration allows for the execution of untrusted scripts as part of the markup. Attackers can exploit this by inserting encoded markup, which is parsed and serialized incorrectly, resulting in live markup that can execute arbitrary code on the user's browser. Applications utilizing LazyHTML to parse untrusted HTML should implement stringent validations to safeguard against these types of attacks.

Affected Version(s)

lazy_html 0.1.0 < 0.1.13

lazy_html 1dee15746c024916b3110af8b168c2f3b3065fbd

References

CVSS V4

Score:
2.3
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Peter Ullrich
Jonatan Kłosko
Jonatan Männchen / EEF
José Valim
.