CVE-2026-92973: Pycontribs ANSI2HTML
Medium severity, CVSS 6.1. EPSS: 0.4% chance of exploitation in the next 30 days.
ansi2html versions 1.7.0a0 through 1.9.3 contain a cross-site scripting vulnerability in OSC 8 hyperlink handling that fails to validate or escape URL targets. Attackers controlling ANSI text input can inject javascript: schemes or terminate href attributes to execute arbitrary scripts in the context of pages displaying converted output.
Affected products
- Pycontribs ANSI2HTML: from 1.7.0a0, before 1.9.4 (fixed in 1.9.4)
Published 2026-09-17. Last modified 2026-09-23.