Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in dashbitco lazy_html allows mutation XSS via a parse and serialize round-trip of attacker-supplied HTML.
LazyHTML.to_html/2 and LazyHTML.Tree.to_html/2 decide whether to escape an element's text from its tag name alone. A style or script element inside SVG or MathML foreign content is parsed with character references decoded, but is serialized as an HTML raw-text element, so its text is emitted unescaped. Encoded markup such as </style><img src=x onerror=...> inside
{
"cna_assigner": "EEF",
"cwe_ids": [
"CWE-79"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/92xxx/CVE-2026-92106.json",
"unresolved_ranges": [
{
"extracted_events": [
{
"introduced": "1dee15746c024916b3110af8b168c2f3b3065fbd"
},
{
"fixed": "f32c7fd6223225b68bc8691c78b6d4a77972f1d5"
}
],
"source": "AFFECTED_FIELD"
}
]
}