CVE Feed

    Dashboard / CVE / CVE-2026-72925

    CVE-2026-72925

    SWC is a TypeScript / JavaScript compiler written in Rust. Prior to @swc/html 1.15.47-nightly-20260729.1 and swc_html_minifier 59.0.0, the minifyJson processing in crates/swc_html_minifier/src/lib.rs parsed and serialized attacker-controlled JSON in application/json and application/ld+json script elements without the escape_json_for_html_script behavior to re-escape less-than signs, allowing a closing script sequence to terminate the element early and execute script in the generated page's origin. This issue is fixed in @swc/html 1.15.47-nightly-20260729.1 and swc_html_minifier 59.0.0.

    Published:Aug 11, 2026
    Last Modified:Aug 13, 2026
    EPS:Aug 11, 2026
    EPSS Score:0.00194
    CVSS Score:6.1

    Affected Products

    Vendor
    Swc Project
    Product
    Html
    Vendor
    Swc Project
    Product
    Swc
    Vendor
    Swc Project
    Product
    Swc Html Minifier

    Exploits

    No exploit reference

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High