CVE-2026-72925Medium· 6.1▾ SunlitSWC is a TypeScript / JavaScript compiler written in Rust. Prior to @swc/html 1.15.47-nightly-20260729.1 and swc_html_minifier 59.0.0, the minifyJson processing in crates/swc_html_minifier/src/lib.rs parsed and serialized attacker-contro…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 33.6 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.2%
Last analysed / modified upstream
SWC is a TypeScript / JavaScript compiler written in Rust. Prior to @swc/html 1.15.47-nightly-20260729.1 and swc_html_minifier 59.0.0, the minifyJson processing in crates/swc_html_minifier/src/lib.rs parsed and serialized attacker-controlled JSON in application/json and application/ld+json script elements without the escape_json_for_html_script behavior to re-escape less-than signs, allowing a closing script sequence to terminate the element early and execute script in the generated page's origin. This issue is fixed in @swc/html 1.15.47-nightly-20260729.1 and swc_html_minifier 59.0.0.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
@swc/html < 1.15.47-nightly-20260729.1swc_html_minifier < 59.0.0Patched in:
@swc/html 1.15.47-nightly-20260729.1swc_html_minifier 59.0.0Connected by shared product, vendor, weakness, or advisory.
CVE-2026-12048Critical· 9.3Stored cross-site scripting in pgAdmin 4's error-rendering and plan-node-rendering paths
CVE-2026-12047Low· 3.5HTML injection in pgAdmin 4's cloud deployment module
CVE-2026-61784Medium· 6.1xhtml-purifier is a Node.js library to take in raw/unknown/untrusted HTML and output cleaned, purified, trusted HTML
GHSA-9395-2g46-rj3fHighdjust: Six template-layer defects emit attacker-controlled markup unescaped (XSS)
GHSA-xjw9-38cr-6372Highdjust: A template binding inherits a context safety grant it never earned (XSS)
CVE-2026-61824High· 8.2Defuddle vulnerable to XSS via unescaped attribute interpolation in site extractors