Cross-Site Scripting Vulnerability in ansi2html by PyContribs
CVE-2026-92973
5.3MEDIUM
What is CVE-2026-92973?
The ansi2html product, versions 1.7.0a0 through 1.9.3, is vulnerable to a cross-site scripting flaw due to improper handling of OSC 8 hyperlinks. This vulnerability allows attackers to exploit unvalidated or non-escaped URL targets in ANSI text input. By injecting malicious javascript schemes or terminating href attributes, attackers can execute arbitrary scripts within the context of the pages that render the converted output, posing a significant security risk to users.
Affected Version(s)
ansi2html 1.7.0a0 < 1.9.4
