{"id":"GHSA-5qr2-v392-m9g8","summary":"SWC HTML minifier may allow script element breakout when minifying embedded JSON","details":"## Impact\n\n`@swc/html` minifies JSON contained in `script` elements such as\n`application/json` and `application/ld+json` by parsing and serializing the\nJSON value.\n\nBefore the patched versions, JSON serialization could convert escaped\nless-than signs such as `\\u003C` into literal `\u003c` characters. If the JSON\ncontained an escaped `\u003c/script\u003e` sequence, the generated HTML could terminate\nthe containing script element early because HTML tokenization occurs before\nthe JSON is consumed.\n\nApplications that minify HTML containing attacker-controlled JSON data could\ntherefore transform inert data into active markup. A crafted payload could\nexecute script in the origin of the generated page.\n\n## Patches\n\nThe issue is fixed in:\n\n- `@swc/html` 1.15.47\n- `swc_html_minifier` 59.0.0\n\nThe minifier now re-escapes less-than signs after JSON serialization, preserving\nthe script element boundary.\n\n## Workarounds\n\nUsers who cannot upgrade can disable JSON minification with:\n\n```js\nawait minify(html, {\n  minifyJson: false,\n});","aliases":["CVE-2026-72925"],"modified":"2026-09-08T18:15:03.995774389Z","published":"2026-09-08T17:58:00Z","database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-09-08T17:58:00Z","nvd_published_at":"2026-08-11T15:17:38Z","cwe_ids":["CWE-116","CWE-79"]},"references":[{"type":"WEB","url":"https://github.com/swc-project/swc/security/advisories/GHSA-5qr2-v392-m9g8"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-72925"},{"type":"WEB","url":"https://github.com/swc-project/swc/pull/12080"},{"type":"WEB","url":"https://github.com/swc-project/swc/commit/e1877b44bdac8abc9fd51e984d584f40f6999832"},{"type":"PACKAGE","url":"https://github.com/swc-project/swc"},{"type":"WEB","url":"https://github.com/swc-project/swc/releases/tag/v1.15.47"},{"type":"WEB","url":"https://github.com/swc-project/swc/releases/tag/v1.15.47-nightly-20260729.1"}],"affected":[{"package":{"name":"@swc/html","ecosystem":"npm","purl":"pkg:npm/%40swc/html"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.15.47-nightly-20260729.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-5qr2-v392-m9g8/GHSA-5qr2-v392-m9g8.json"}},{"package":{"name":"swc_html_minifier","ecosystem":"crates.io","purl":"pkg:cargo/swc_html_minifier"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"59.0.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-5qr2-v392-m9g8/GHSA-5qr2-v392-m9g8.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}