{"id":"CVE-2026-72925","title":"SWC is a TypeScript / JavaScript compiler written in Rust","summary":"SWC is a TypeScript / JavaScript compiler written in Rust. Prior to @swc/html 1.15.47-nightly-20260729.1 and swc_html_minifier 59.0.0, the minifyJson processing in crates/swc_html_minifier/src/lib.rs parsed and serialized attacker-contro…","severity":"medium","cvss":6.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","cwe":["CWE-79","CWE-116"],"vendor":"swc","product":"@swc/html","affected":["@swc/html < 1.15.47-nightly-20260729.1","swc_html_minifier < 59.0.0"],"patched":["@swc/html 1.15.47-nightly-20260729.1","swc_html_minifier 59.0.0"],"published":"2026-08-11","updated":"2026-09-18","sourceUpdated":"2026-09-18T20:05:53.723","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-72925","references":[{"url":"https://github.com/swc-project/swc/commit/e1877b44bdac8abc9fd51e984d584f40f6999832","label":"security-advisories@github.com"},{"url":"https://github.com/swc-project/swc/pull/12080","label":"security-advisories@github.com"},{"url":"https://github.com/swc-project/swc/releases/tag/v1.15.47","label":"security-advisories@github.com"},{"url":"https://github.com/swc-project/swc/releases/tag/v1.15.47-nightly-20260729.1","label":"security-advisories@github.com"},{"url":"https://github.com/swc-project/swc/security/advisories/GHSA-5qr2-v392-m9g8","label":"security-advisories@github.com"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-72925"},{"url":"https://github.com/swc-project/swc"},{"url":"https://github.com/advisories/GHSA-5qr2-v392-m9g8"}],"tags":["nvd","osv","npm","ghsa"],"epss":0.00338,"epssPercentile":0.24519,"aliases":["GHSA-5qr2-v392-m9g8"],"ecosystem":"npm","ingestedAt":"2026-09-08T19:08:49.635Z","slug":"CVE-2026-72925","body":"## Overview\n\nSWC is a TypeScript / JavaScript compiler written in Rust. Prior to @swc/html 1.15.47-nightly-20260729.1 and swc_html_minifier 59.0.0, the minifyJson processing in crates/swc_html_minifier/src/lib.rs parsed and serialized attacker-controlled JSON in application/json and application/ld+json script elements without the escape_json_for_html_script behavior to re-escape less-than signs, allowing a closing script sequence to terminate the element early and execute script in the generated page's origin. This issue is fixed in @swc/html 1.15.47-nightly-20260729.1 and swc_html_minifier 59.0.0.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Package advisory (CVE-2026-72925)\n\nAffected packages:\n\n- `@swc/html < 1.15.47-nightly-20260729.1`\n- `swc_html_minifier < 59.0.0`\n\nPatched in:\n\n- `@swc/html 1.15.47-nightly-20260729.1`\n- `swc_html_minifier 59.0.0`\n\nSource: https://osv.dev/vulnerability/GHSA-5qr2-v392-m9g8","depth":"sunlit","depthScore":34,"depthScoreParts":{"impact":33.6,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}