Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in dashbitco lazy_html allows mutation XSS via a parse and serialize round-trip of attacker-supplied HTML.
LazyHTML.to_html/2 and LazyHTML.Tree.to_html/2 decide whether to escape an element's text from its tag name alone. A style or script element inside SVG or MathML foreign content is parsed with character references decoded, but is serialized as an HTML raw-text element, so its text is emitted unescaped. Encoded markup such as </style><img src=x onerror=...> inside <svg><style> therefore closes the element on re-parse and becomes live markup. Applications that parse untrusted HTML with lazy_html, filter the document or tree, and serialize it for display are affected, since the payload is a plain text node that no element or attribute filter sees.
This issue affects lazy_html: from 0.1.0 before 0.1.13.
An attacker who can submit HTML to an application that sanitizes it with lazy_html can run script in the browsers of users who view the sanitized output.
{
"capec_ids": [
"CAPEC-63"
],
"cpe_ids": [
"cpe:2.3:a:dashbitco:lazy_html:*:*:*:*:*:*:*:*"
],
"cwe_ids": [
"CWE-79"
]
}"https://cna.erlef.org/osv/EEF-CVE-2026-92106.json"
[
{
"deprecated": false,
"digest": {
"line_hashes": [
"90580969371312759060218553849842762155",
"280370715495015491356308257904647850745",
"313156110902979146990051129963006853764",
"76688445630280347675906510080577143580"
],
"threshold": 0.9
},
"id": "EEF-CVE-2026-92106-3b362797",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/dashbitco/lazy_html/commit/f32c7fd6223225b68bc8691c78b6d4a77972f1d5",
"target": {
"file": "c_src/lazy_html.cpp"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "310579417436848425715483271822210258623",
"length": 301
},
"id": "EEF-CVE-2026-92106-48a8e963",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/dashbitco/lazy_html/commit/f32c7fd6223225b68bc8691c78b6d4a77972f1d5",
"target": {
"file": "c_src/lazy_html.cpp",
"function": "is_noescape_text_node"
}
}
]
"2026-09-25T14:00:18Z"