{"id":"CVE-2020-26293","details":"HtmlSanitizer is a .NET library for cleaning HTML fragments and documents from constructs that can lead to XSS attacks. In HtmlSanitizer before version 5.0.372, there is a possible XSS bypass if style tag is allowed. If you have explicitly allowed the `\u003cstyle\u003e` tag, an attacker could craft HTML that includes script after passing through the sanitizer. The default settings disallow the `\u003cstyle\u003e` tag so there is no risk if you have not explicitly allowed the `\u003cstyle\u003e` tag. The problem has been fixed in version 5.0.372.","aliases":["GHSA-8j9v-h2vp-2hhv"],"modified":"2026-07-09T01:07:38.108608Z","published":"2021-01-04T19:15:14.970Z","references":[{"type":"ADVISORY","url":"https://github.com/mganss/HtmlSanitizer/releases/tag/v5.0.372"},{"type":"ADVISORY","url":"https://github.com/mganss/HtmlSanitizer/security/advisories/GHSA-8j9v-h2vp-2hhv"},{"type":"ADVISORY","url":"https://www.nuget.org/packages/HtmlSanitizer/"},{"type":"FIX","url":"https://github.com/mganss/HtmlSanitizer/commit/a3a7602a44d4155d51ec0fbbedc2a49e9c7e2eb8"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/mganss/htmlsanitizer","events":[{"introduced":"0"},{"fixed":"a3a7602a44d4155d51ec0fbbedc2a49e9c7e2eb8"}],"database_specific":{"cpe":"cpe:2.3:a:htmlsanitizer_project:htmlsanitizer:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"5.0.372"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["v5.0.371","v5.0.368","v5.0.367","v5.0.366","v5.0.365","v5.0.364","v5.0.363","v5.0.358","v5.0.355","v5.0.354","v5.0.343","v5.0.342","v5.0.332","v5.0.331","v5.0.328","v5.0.325","v5.0.322","v5.0.319","v5.0.316","v5.0.313","v5.0.310","v5.0.307","v5.0.304","v5.0.303","v5.0.298","v5.0.297","v5.0.296","v5.0.293","v5.0.292","v5.0.291","v5.0.290","v5.0.287","v5.0.283","v5.0.280","v5.0.277","v5.0.274","v5.0.272","v5.0.269","v5.0.266","v5.0.263","v5.0.260","v5.0.257","v5.0.250","v5.0.249","v5.0.248","v5.0.245","v5.0.244","v5.0.239","v5.0.236","v5.0.233","v4.0.230","v4.0.229","v4.0.228","v4.0.219","v4.0.217","v4.0.212","v4.0.211","v4.0.210","v4.0.209","v4.0.207","v4.0.205","v4.0.204","v4.0.201","v4.0.199","v4.0.193","v4.0.192","v4.0.191","v4.0.189","v4.0.188","v4.0.187","v4.0.186","v4.0.185","v4.0.183","v4.0.182","v4.0.181","v4.0.180","v4.0.179","v3.5.169-beta","v3.5.168-beta","v3.5.167-beta","v3.4.156","v3.4.152-beta","v3.3.148-beta","v3.3.147-beta","v3.3.146-beta","v3.3.145-beta","v3.3.144-beta","v3.3.143-beta","v3.3.142","v3.3.140-beta","v3.3.134-beta","v3.3.132-beta","v3.3.131-beta","v3.3.130-beta","v3.3.129-beta","v3.3.128-beta","v3.3.127-beta","v3.3.126-beta","v3.3.125-beta","v3.3.122-beta","v3.2.105","v3.2.103","v3.2.100","v3.1.98","v3.1.93","v3.1.91","v3.1.79","v3.1.76"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-26293.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}