swc_html_minifier
HTML minifier
Activity
- Latest release
- 1mo ago
- Total releases
- 1059
- Cadence
- ~8 days
- Last 12 months
- 28
Reach
- Downloads
- 1.5M
Details
- License
- Apache-2.0
- First release
- Apr 23, 2022
| Version | Released | |
|---|---|---|
61.0.0
major
|
61.0.0
major
Dependencies (25)
+ 17 more
Changelog
Compare changes
|
|
60.0.0
major
|
60.0.0
major
Dependencies (25)
+ 17 more
Changelog
Compare changes
|
|
59.0.0
unknown
|
59.0.0
unknown
Dependencies (25)
+ 17 more
Changelog
Compare changes
|
|
58.0.0
unknown
1 CVE
CVE-2026-72925
GHSA-5qr2-v392-m9g8
Sep 08, 2026
SWC HTML minifier may allow script element breakout when minifying embedded JSON
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Impact
Before the patched versions, JSON serialization could convert escaped
less-than signs such as Applications that minify HTML containing attacker-controlled JSON data could therefore transform inert data into active markup. A crafted payload could execute script in the origin of the generated page. PatchesThe issue is fixed in:
The minifier now re-escapes less-than signs after JSON serialization, preserving the script element boundary. WorkaroundsUsers who cannot upgrade can disable JSON minification with:
Fixed in
59.0.0
References
Updated Sep 08, 2026 · Source: OSV.dev |
58.0.0
unknown
Dependencies (25)
+ 17 more
Changelog
Compare changes
|
|
57.0.0
unknown
1 CVE
CVE-2026-72925
GHSA-5qr2-v392-m9g8
Sep 08, 2026
SWC HTML minifier may allow script element breakout when minifying embedded JSON
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Impact
Before the patched versions, JSON serialization could convert escaped
less-than signs such as Applications that minify HTML containing attacker-controlled JSON data could therefore transform inert data into active markup. A crafted payload could execute script in the origin of the generated page. PatchesThe issue is fixed in:
The minifier now re-escapes less-than signs after JSON serialization, preserving the script element boundary. WorkaroundsUsers who cannot upgrade can disable JSON minification with:
Fixed in
59.0.0
References
Updated Sep 08, 2026 · Source: OSV.dev |
57.0.0
unknown
Dependencies (25)
+ 17 more
Changelog
Compare changes
|
|
56.0.0
unknown
1 CVE
CVE-2026-72925
GHSA-5qr2-v392-m9g8
Sep 08, 2026
SWC HTML minifier may allow script element breakout when minifying embedded JSON
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Impact
Before the patched versions, JSON serialization could convert escaped
less-than signs such as Applications that minify HTML containing attacker-controlled JSON data could therefore transform inert data into active markup. A crafted payload could execute script in the origin of the generated page. PatchesThe issue is fixed in:
The minifier now re-escapes less-than signs after JSON serialization, preserving the script element boundary. WorkaroundsUsers who cannot upgrade can disable JSON minification with:
Fixed in
59.0.0
References
Updated Sep 08, 2026 · Source: OSV.dev |
56.0.0
unknown
Dependencies (25)
+ 17 more
Changelog
Compare changes
|
|
55.0.0
unknown
1 CVE
CVE-2026-72925
GHSA-5qr2-v392-m9g8
Sep 08, 2026
SWC HTML minifier may allow script element breakout when minifying embedded JSON
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Impact
Before the patched versions, JSON serialization could convert escaped
less-than signs such as Applications that minify HTML containing attacker-controlled JSON data could therefore transform inert data into active markup. A crafted payload could execute script in the origin of the generated page. PatchesThe issue is fixed in:
The minifier now re-escapes less-than signs after JSON serialization, preserving the script element boundary. WorkaroundsUsers who cannot upgrade can disable JSON minification with:
Fixed in
59.0.0
References
Updated Sep 08, 2026 · Source: OSV.dev |
55.0.0
unknown
Dependencies (25)
+ 17 more
Changelog
Compare changes
|
|
54.0.0
unknown
1 CVE
CVE-2026-72925
GHSA-5qr2-v392-m9g8
Sep 08, 2026
SWC HTML minifier may allow script element breakout when minifying embedded JSON
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Impact
Before the patched versions, JSON serialization could convert escaped
less-than signs such as Applications that minify HTML containing attacker-controlled JSON data could therefore transform inert data into active markup. A crafted payload could execute script in the origin of the generated page. PatchesThe issue is fixed in:
The minifier now re-escapes less-than signs after JSON serialization, preserving the script element boundary. WorkaroundsUsers who cannot upgrade can disable JSON minification with:
Fixed in
59.0.0
References
Updated Sep 08, 2026 · Source: OSV.dev |
54.0.0
unknown
Dependencies (25)
+ 17 more
Changelog
Compare changes
|
|
53.0.0
unknown
1 CVE
CVE-2026-72925
GHSA-5qr2-v392-m9g8
Sep 08, 2026
SWC HTML minifier may allow script element breakout when minifying embedded JSON
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Impact
Before the patched versions, JSON serialization could convert escaped
less-than signs such as Applications that minify HTML containing attacker-controlled JSON data could therefore transform inert data into active markup. A crafted payload could execute script in the origin of the generated page. PatchesThe issue is fixed in:
The minifier now re-escapes less-than signs after JSON serialization, preserving the script element boundary. WorkaroundsUsers who cannot upgrade can disable JSON minification with:
Fixed in
59.0.0
References
Updated Sep 08, 2026 · Source: OSV.dev |
53.0.0
unknown
Dependencies (25)
+ 17 more
Changelog
Compare changes
|
|
52.0.0
unknown
1 CVE
CVE-2026-72925
GHSA-5qr2-v392-m9g8
Sep 08, 2026
SWC HTML minifier may allow script element breakout when minifying embedded JSON
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Impact
Before the patched versions, JSON serialization could convert escaped
less-than signs such as Applications that minify HTML containing attacker-controlled JSON data could therefore transform inert data into active markup. A crafted payload could execute script in the origin of the generated page. PatchesThe issue is fixed in:
The minifier now re-escapes less-than signs after JSON serialization, preserving the script element boundary. WorkaroundsUsers who cannot upgrade can disable JSON minification with:
Fixed in
59.0.0
References
Updated Sep 08, 2026 · Source: OSV.dev |
52.0.0
unknown
Dependencies (25)
+ 17 more
Changelog
Compare changes
|
|
51.0.0
unknown
1 CVE
CVE-2026-72925
GHSA-5qr2-v392-m9g8
Sep 08, 2026
SWC HTML minifier may allow script element breakout when minifying embedded JSON
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Impact
Before the patched versions, JSON serialization could convert escaped
less-than signs such as Applications that minify HTML containing attacker-controlled JSON data could therefore transform inert data into active markup. A crafted payload could execute script in the origin of the generated page. PatchesThe issue is fixed in:
The minifier now re-escapes less-than signs after JSON serialization, preserving the script element boundary. WorkaroundsUsers who cannot upgrade can disable JSON minification with:
Fixed in
59.0.0
References
Updated Sep 08, 2026 · Source: OSV.dev |
51.0.0
unknown
Dependencies (25)
+ 17 more
Changelog
Compare changes
|
|
50.0.0
unknown
1 CVE
CVE-2026-72925
GHSA-5qr2-v392-m9g8
Sep 08, 2026
SWC HTML minifier may allow script element breakout when minifying embedded JSON
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Impact
Before the patched versions, JSON serialization could convert escaped
less-than signs such as Applications that minify HTML containing attacker-controlled JSON data could therefore transform inert data into active markup. A crafted payload could execute script in the origin of the generated page. PatchesThe issue is fixed in:
The minifier now re-escapes less-than signs after JSON serialization, preserving the script element boundary. WorkaroundsUsers who cannot upgrade can disable JSON minification with:
Fixed in
59.0.0
References
Updated Sep 08, 2026 · Source: OSV.dev |
50.0.0
unknown
Dependencies (25)
+ 17 more
Changelog
Compare changes
|
|
49.0.0
unknown
1 CVE
CVE-2026-72925
GHSA-5qr2-v392-m9g8
Sep 08, 2026
SWC HTML minifier may allow script element breakout when minifying embedded JSON
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Impact
Before the patched versions, JSON serialization could convert escaped
less-than signs such as Applications that minify HTML containing attacker-controlled JSON data could therefore transform inert data into active markup. A crafted payload could execute script in the origin of the generated page. PatchesThe issue is fixed in:
The minifier now re-escapes less-than signs after JSON serialization, preserving the script element boundary. WorkaroundsUsers who cannot upgrade can disable JSON minification with:
Fixed in
59.0.0
References
Updated Sep 08, 2026 · Source: OSV.dev |
49.0.0
unknown
Dependencies (25)
+ 17 more
Changelog
Compare changes
|
|
48.0.0
unknown
1 CVE
CVE-2026-72925
GHSA-5qr2-v392-m9g8
Sep 08, 2026
SWC HTML minifier may allow script element breakout when minifying embedded JSON
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Impact
Before the patched versions, JSON serialization could convert escaped
less-than signs such as Applications that minify HTML containing attacker-controlled JSON data could therefore transform inert data into active markup. A crafted payload could execute script in the origin of the generated page. PatchesThe issue is fixed in:
The minifier now re-escapes less-than signs after JSON serialization, preserving the script element boundary. WorkaroundsUsers who cannot upgrade can disable JSON minification with:
Fixed in
59.0.0
References
Updated Sep 08, 2026 · Source: OSV.dev |
48.0.0
unknown
Dependencies (25)
+ 17 more
Changelog
Compare changes
|
|
47.0.0
unknown
1 CVE
CVE-2026-72925
GHSA-5qr2-v392-m9g8
Sep 08, 2026
SWC HTML minifier may allow script element breakout when minifying embedded JSON
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Impact
Before the patched versions, JSON serialization could convert escaped
less-than signs such as Applications that minify HTML containing attacker-controlled JSON data could therefore transform inert data into active markup. A crafted payload could execute script in the origin of the generated page. PatchesThe issue is fixed in:
The minifier now re-escapes less-than signs after JSON serialization, preserving the script element boundary. WorkaroundsUsers who cannot upgrade can disable JSON minification with:
Fixed in
59.0.0
References
Updated Sep 08, 2026 · Source: OSV.dev |
47.0.0
unknown
Dependencies (25)
+ 17 more
Changelog
Compare changes
|
|
46.0.0
unknown
1 CVE
CVE-2026-72925
GHSA-5qr2-v392-m9g8
Sep 08, 2026
SWC HTML minifier may allow script element breakout when minifying embedded JSON
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Impact
Before the patched versions, JSON serialization could convert escaped
less-than signs such as Applications that minify HTML containing attacker-controlled JSON data could therefore transform inert data into active markup. A crafted payload could execute script in the origin of the generated page. PatchesThe issue is fixed in:
The minifier now re-escapes less-than signs after JSON serialization, preserving the script element boundary. WorkaroundsUsers who cannot upgrade can disable JSON minification with:
Fixed in
59.0.0
References
Updated Sep 08, 2026 · Source: OSV.dev |
46.0.0
unknown
Dependencies (25)
+ 17 more
Changelog
Compare changes
|
|
45.0.0
unknown
1 CVE
CVE-2026-72925
GHSA-5qr2-v392-m9g8
Sep 08, 2026
SWC HTML minifier may allow script element breakout when minifying embedded JSON
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Impact
Before the patched versions, JSON serialization could convert escaped
less-than signs such as Applications that minify HTML containing attacker-controlled JSON data could therefore transform inert data into active markup. A crafted payload could execute script in the origin of the generated page. PatchesThe issue is fixed in:
The minifier now re-escapes less-than signs after JSON serialization, preserving the script element boundary. WorkaroundsUsers who cannot upgrade can disable JSON minification with:
Fixed in
59.0.0
References
Updated Sep 08, 2026 · Source: OSV.dev |
45.0.0
unknown
Dependencies (25)
+ 17 more
Changelog
Compare changes
|
|
44.0.0
unknown
1 CVE
CVE-2026-72925
GHSA-5qr2-v392-m9g8
Sep 08, 2026
SWC HTML minifier may allow script element breakout when minifying embedded JSON
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Impact
Before the patched versions, JSON serialization could convert escaped
less-than signs such as Applications that minify HTML containing attacker-controlled JSON data could therefore transform inert data into active markup. A crafted payload could execute script in the origin of the generated page. PatchesThe issue is fixed in:
The minifier now re-escapes less-than signs after JSON serialization, preserving the script element boundary. WorkaroundsUsers who cannot upgrade can disable JSON minification with:
Fixed in
59.0.0
References
Updated Sep 08, 2026 · Source: OSV.dev |
44.0.0
unknown
Dependencies (25)
+ 17 more
Changelog
Compare changes
|
|
43.0.0
unknown
1 CVE
CVE-2026-72925
GHSA-5qr2-v392-m9g8
Sep 08, 2026
SWC HTML minifier may allow script element breakout when minifying embedded JSON
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Impact
Before the patched versions, JSON serialization could convert escaped
less-than signs such as Applications that minify HTML containing attacker-controlled JSON data could therefore transform inert data into active markup. A crafted payload could execute script in the origin of the generated page. PatchesThe issue is fixed in:
The minifier now re-escapes less-than signs after JSON serialization, preserving the script element boundary. WorkaroundsUsers who cannot upgrade can disable JSON minification with:
Fixed in
59.0.0
References
Updated Sep 08, 2026 · Source: OSV.dev |
43.0.0
unknown
Dependencies (25)
+ 17 more
Changelog
Compare changes
|
|
42.0.0
unknown
1 CVE
CVE-2026-72925
GHSA-5qr2-v392-m9g8
Sep 08, 2026
SWC HTML minifier may allow script element breakout when minifying embedded JSON
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Impact
Before the patched versions, JSON serialization could convert escaped
less-than signs such as Applications that minify HTML containing attacker-controlled JSON data could therefore transform inert data into active markup. A crafted payload could execute script in the origin of the generated page. PatchesThe issue is fixed in:
The minifier now re-escapes less-than signs after JSON serialization, preserving the script element boundary. WorkaroundsUsers who cannot upgrade can disable JSON minification with:
Fixed in
59.0.0
References
Updated Sep 08, 2026 · Source: OSV.dev |
42.0.0
unknown
Dependencies (25)
+ 17 more
Changelog
Compare changes
|
|
41.0.0
unknown
1 CVE
CVE-2026-72925
GHSA-5qr2-v392-m9g8
Sep 08, 2026
SWC HTML minifier may allow script element breakout when minifying embedded JSON
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Impact
Before the patched versions, JSON serialization could convert escaped
less-than signs such as Applications that minify HTML containing attacker-controlled JSON data could therefore transform inert data into active markup. A crafted payload could execute script in the origin of the generated page. PatchesThe issue is fixed in:
The minifier now re-escapes less-than signs after JSON serialization, preserving the script element boundary. WorkaroundsUsers who cannot upgrade can disable JSON minification with:
Fixed in
59.0.0
References
Updated Sep 08, 2026 · Source: OSV.dev |
41.0.0
unknown
Dependencies (25)
+ 17 more
Changelog
Compare changes
|
|
40.0.0
unknown
1 CVE
CVE-2026-72925
GHSA-5qr2-v392-m9g8
Sep 08, 2026
SWC HTML minifier may allow script element breakout when minifying embedded JSON
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Impact
Before the patched versions, JSON serialization could convert escaped
less-than signs such as Applications that minify HTML containing attacker-controlled JSON data could therefore transform inert data into active markup. A crafted payload could execute script in the origin of the generated page. PatchesThe issue is fixed in:
The minifier now re-escapes less-than signs after JSON serialization, preserving the script element boundary. WorkaroundsUsers who cannot upgrade can disable JSON minification with:
Fixed in
59.0.0
References
Updated Sep 08, 2026 · Source: OSV.dev |
40.0.0
unknown
Dependencies (25)
+ 17 more
Changelog
Compare changes
|
|
39.0.0
unknown
1 CVE
CVE-2026-72925
GHSA-5qr2-v392-m9g8
Sep 08, 2026
SWC HTML minifier may allow script element breakout when minifying embedded JSON
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Impact
Before the patched versions, JSON serialization could convert escaped
less-than signs such as Applications that minify HTML containing attacker-controlled JSON data could therefore transform inert data into active markup. A crafted payload could execute script in the origin of the generated page. PatchesThe issue is fixed in:
The minifier now re-escapes less-than signs after JSON serialization, preserving the script element boundary. WorkaroundsUsers who cannot upgrade can disable JSON minification with:
Fixed in
59.0.0
References
Updated Sep 08, 2026 · Source: OSV.dev |
39.0.0
unknown
Dependencies (25)
+ 17 more
Changelog
Compare changes
|
|
38.0.0
unknown
1 CVE
CVE-2026-72925
GHSA-5qr2-v392-m9g8
Sep 08, 2026
SWC HTML minifier may allow script element breakout when minifying embedded JSON
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Impact
Before the patched versions, JSON serialization could convert escaped
less-than signs such as Applications that minify HTML containing attacker-controlled JSON data could therefore transform inert data into active markup. A crafted payload could execute script in the origin of the generated page. PatchesThe issue is fixed in:
The minifier now re-escapes less-than signs after JSON serialization, preserving the script element boundary. WorkaroundsUsers who cannot upgrade can disable JSON minification with:
Fixed in
59.0.0
References
Updated Sep 08, 2026 · Source: OSV.dev |
38.0.0
unknown
Dependencies (25)
+ 17 more
Changelog
Compare changes
|
|
37.0.0
unknown
1 CVE
CVE-2026-72925
GHSA-5qr2-v392-m9g8
Sep 08, 2026
SWC HTML minifier may allow script element breakout when minifying embedded JSON
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Impact
Before the patched versions, JSON serialization could convert escaped
less-than signs such as Applications that minify HTML containing attacker-controlled JSON data could therefore transform inert data into active markup. A crafted payload could execute script in the origin of the generated page. PatchesThe issue is fixed in:
The minifier now re-escapes less-than signs after JSON serialization, preserving the script element boundary. WorkaroundsUsers who cannot upgrade can disable JSON minification with:
Fixed in
59.0.0
References
Updated Sep 08, 2026 · Source: OSV.dev |
37.0.0
unknown
Dependencies (25)
+ 17 more
Changelog
Compare changes
|
|
36.0.0
unknown
1 CVE
CVE-2026-72925
GHSA-5qr2-v392-m9g8
Sep 08, 2026
SWC HTML minifier may allow script element breakout when minifying embedded JSON
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Impact
Before the patched versions, JSON serialization could convert escaped
less-than signs such as Applications that minify HTML containing attacker-controlled JSON data could therefore transform inert data into active markup. A crafted payload could execute script in the origin of the generated page. PatchesThe issue is fixed in:
The minifier now re-escapes less-than signs after JSON serialization, preserving the script element boundary. WorkaroundsUsers who cannot upgrade can disable JSON minification with:
Fixed in
59.0.0
References
Updated Sep 08, 2026 · Source: OSV.dev |
36.0.0
unknown
Dependencies (25)
+ 17 more
Changelog
Compare changes
|
|
35.0.0
unknown
1 CVE
CVE-2026-72925
GHSA-5qr2-v392-m9g8
Sep 08, 2026
SWC HTML minifier may allow script element breakout when minifying embedded JSON
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Impact
Before the patched versions, JSON serialization could convert escaped
less-than signs such as Applications that minify HTML containing attacker-controlled JSON data could therefore transform inert data into active markup. A crafted payload could execute script in the origin of the generated page. PatchesThe issue is fixed in:
The minifier now re-escapes less-than signs after JSON serialization, preserving the script element boundary. WorkaroundsUsers who cannot upgrade can disable JSON minification with:
Fixed in
59.0.0
References
Updated Sep 08, 2026 · Source: OSV.dev |
35.0.0
unknown
Dependencies (25)
+ 17 more
Changelog
Compare changes
|
|
34.0.0
unknown
1 CVE
CVE-2026-72925
GHSA-5qr2-v392-m9g8
Sep 08, 2026
SWC HTML minifier may allow script element breakout when minifying embedded JSON
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Impact
Before the patched versions, JSON serialization could convert escaped
less-than signs such as Applications that minify HTML containing attacker-controlled JSON data could therefore transform inert data into active markup. A crafted payload could execute script in the origin of the generated page. PatchesThe issue is fixed in:
The minifier now re-escapes less-than signs after JSON serialization, preserving the script element boundary. WorkaroundsUsers who cannot upgrade can disable JSON minification with:
Fixed in
59.0.0
References
Updated Sep 08, 2026 · Source: OSV.dev |
34.0.0
unknown
Dependencies (25)
+ 17 more
Changelog
Compare changes
|
|
33.0.0
unknown
1 CVE
CVE-2026-72925
GHSA-5qr2-v392-m9g8
Sep 08, 2026
SWC HTML minifier may allow script element breakout when minifying embedded JSON
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Impact
Before the patched versions, JSON serialization could convert escaped
less-than signs such as Applications that minify HTML containing attacker-controlled JSON data could therefore transform inert data into active markup. A crafted payload could execute script in the origin of the generated page. PatchesThe issue is fixed in:
The minifier now re-escapes less-than signs after JSON serialization, preserving the script element boundary. WorkaroundsUsers who cannot upgrade can disable JSON minification with:
Fixed in
59.0.0
References
Updated Sep 08, 2026 · Source: OSV.dev |
33.0.0
unknown
Dependencies (25)
+ 17 more
Changelog
Compare changes
|
|
32.0.0
unknown
1 CVE
CVE-2026-72925
GHSA-5qr2-v392-m9g8
Sep 08, 2026
SWC HTML minifier may allow script element breakout when minifying embedded JSON
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Impact
Before the patched versions, JSON serialization could convert escaped
less-than signs such as Applications that minify HTML containing attacker-controlled JSON data could therefore transform inert data into active markup. A crafted payload could execute script in the origin of the generated page. PatchesThe issue is fixed in:
The minifier now re-escapes less-than signs after JSON serialization, preserving the script element boundary. WorkaroundsUsers who cannot upgrade can disable JSON minification with:
Fixed in
59.0.0
References
Updated Sep 08, 2026 · Source: OSV.dev |
32.0.0
unknown
Dependencies (25)
+ 17 more
Changelog
Compare changes
|
|
31.0.0
unknown
1 CVE
CVE-2026-72925
GHSA-5qr2-v392-m9g8
Sep 08, 2026
SWC HTML minifier may allow script element breakout when minifying embedded JSON
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Impact
Before the patched versions, JSON serialization could convert escaped
less-than signs such as Applications that minify HTML containing attacker-controlled JSON data could therefore transform inert data into active markup. A crafted payload could execute script in the origin of the generated page. PatchesThe issue is fixed in:
The minifier now re-escapes less-than signs after JSON serialization, preserving the script element boundary. WorkaroundsUsers who cannot upgrade can disable JSON minification with:
Fixed in
59.0.0
References
Updated Sep 08, 2026 · Source: OSV.dev |
31.0.0
unknown
Dependencies (25)
+ 17 more
Changelog
Compare changes
|
|
30.0.0
unknown
1 CVE
CVE-2026-72925
GHSA-5qr2-v392-m9g8
Sep 08, 2026
SWC HTML minifier may allow script element breakout when minifying embedded JSON
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Impact
Before the patched versions, JSON serialization could convert escaped
less-than signs such as Applications that minify HTML containing attacker-controlled JSON data could therefore transform inert data into active markup. A crafted payload could execute script in the origin of the generated page. PatchesThe issue is fixed in:
The minifier now re-escapes less-than signs after JSON serialization, preserving the script element boundary. WorkaroundsUsers who cannot upgrade can disable JSON minification with:
Fixed in
59.0.0
References
Updated Sep 08, 2026 · Source: OSV.dev |
30.0.0
unknown
Dependencies (25)
+ 17 more
Changelog
Compare changes
|
|
29.0.0
unknown
1 CVE
CVE-2026-72925
GHSA-5qr2-v392-m9g8
Sep 08, 2026
SWC HTML minifier may allow script element breakout when minifying embedded JSON
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Impact
Before the patched versions, JSON serialization could convert escaped
less-than signs such as Applications that minify HTML containing attacker-controlled JSON data could therefore transform inert data into active markup. A crafted payload could execute script in the origin of the generated page. PatchesThe issue is fixed in:
The minifier now re-escapes less-than signs after JSON serialization, preserving the script element boundary. WorkaroundsUsers who cannot upgrade can disable JSON minification with:
Fixed in
59.0.0
References
Updated Sep 08, 2026 · Source: OSV.dev |
29.0.0
unknown
Dependencies (25)
+ 17 more
Changelog
Compare changes
|
|
28.0.0
unknown
1 CVE
CVE-2026-72925
GHSA-5qr2-v392-m9g8
Sep 08, 2026
SWC HTML minifier may allow script element breakout when minifying embedded JSON
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Impact
Before the patched versions, JSON serialization could convert escaped
less-than signs such as Applications that minify HTML containing attacker-controlled JSON data could therefore transform inert data into active markup. A crafted payload could execute script in the origin of the generated page. PatchesThe issue is fixed in:
The minifier now re-escapes less-than signs after JSON serialization, preserving the script element boundary. WorkaroundsUsers who cannot upgrade can disable JSON minification with:
Fixed in
59.0.0
References
Updated Sep 08, 2026 · Source: OSV.dev |
28.0.0
unknown
Dependencies (25)
+ 17 more
Changelog
Compare changes
|
|
27.0.1
unknown
1 CVE
CVE-2026-72925
GHSA-5qr2-v392-m9g8
Sep 08, 2026
SWC HTML minifier may allow script element breakout when minifying embedded JSON
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Impact
Before the patched versions, JSON serialization could convert escaped
less-than signs such as Applications that minify HTML containing attacker-controlled JSON data could therefore transform inert data into active markup. A crafted payload could execute script in the origin of the generated page. PatchesThe issue is fixed in:
The minifier now re-escapes less-than signs after JSON serialization, preserving the script element boundary. WorkaroundsUsers who cannot upgrade can disable JSON minification with:
Fixed in
59.0.0
References
Updated Sep 08, 2026 · Source: OSV.dev |
27.0.1
unknown
Dependencies (25)
+ 17 more
Changelog
Compare changes
|
|
27.0.0
unknown
1 CVE
CVE-2026-72925
GHSA-5qr2-v392-m9g8
Sep 08, 2026
SWC HTML minifier may allow script element breakout when minifying embedded JSON
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Impact
Before the patched versions, JSON serialization could convert escaped
less-than signs such as Applications that minify HTML containing attacker-controlled JSON data could therefore transform inert data into active markup. A crafted payload could execute script in the origin of the generated page. PatchesThe issue is fixed in:
The minifier now re-escapes less-than signs after JSON serialization, preserving the script element boundary. WorkaroundsUsers who cannot upgrade can disable JSON minification with:
Fixed in
59.0.0
References
Updated Sep 08, 2026 · Source: OSV.dev |
27.0.0
unknown
Dependencies (25)
+ 17 more
Changelog
Compare changes
|
|
26.0.0
unknown
1 CVE
CVE-2026-72925
GHSA-5qr2-v392-m9g8
Sep 08, 2026
SWC HTML minifier may allow script element breakout when minifying embedded JSON
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Impact
Before the patched versions, JSON serialization could convert escaped
less-than signs such as Applications that minify HTML containing attacker-controlled JSON data could therefore transform inert data into active markup. A crafted payload could execute script in the origin of the generated page. PatchesThe issue is fixed in:
The minifier now re-escapes less-than signs after JSON serialization, preserving the script element boundary. WorkaroundsUsers who cannot upgrade can disable JSON minification with:
Fixed in
59.0.0
References
Updated Sep 08, 2026 · Source: OSV.dev |
26.0.0
unknown
Dependencies (25)
+ 17 more
Changelog
Compare changes
|
|
25.0.0
unknown
1 CVE
CVE-2026-72925
GHSA-5qr2-v392-m9g8
Sep 08, 2026
SWC HTML minifier may allow script element breakout when minifying embedded JSON
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Impact
Before the patched versions, JSON serialization could convert escaped
less-than signs such as Applications that minify HTML containing attacker-controlled JSON data could therefore transform inert data into active markup. A crafted payload could execute script in the origin of the generated page. PatchesThe issue is fixed in:
The minifier now re-escapes less-than signs after JSON serialization, preserving the script element boundary. WorkaroundsUsers who cannot upgrade can disable JSON minification with:
Fixed in
59.0.0
References
Updated Sep 08, 2026 · Source: OSV.dev |
25.0.0
unknown
Dependencies (25)
+ 17 more
Changelog
Compare changes
|
|
24.0.1
unknown
1 CVE
CVE-2026-72925
GHSA-5qr2-v392-m9g8
Sep 08, 2026
SWC HTML minifier may allow script element breakout when minifying embedded JSON
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Impact
Before the patched versions, JSON serialization could convert escaped
less-than signs such as Applications that minify HTML containing attacker-controlled JSON data could therefore transform inert data into active markup. A crafted payload could execute script in the origin of the generated page. PatchesThe issue is fixed in:
The minifier now re-escapes less-than signs after JSON serialization, preserving the script element boundary. WorkaroundsUsers who cannot upgrade can disable JSON minification with:
Fixed in
59.0.0
References
Updated Sep 08, 2026 · Source: OSV.dev |
24.0.1
unknown
Dependencies (25)
+ 17 more
Changelog
Compare changes
|
|
24.0.0
unknown
1 CVE
CVE-2026-72925
GHSA-5qr2-v392-m9g8
Sep 08, 2026
SWC HTML minifier may allow script element breakout when minifying embedded JSON
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Impact
Before the patched versions, JSON serialization could convert escaped
less-than signs such as Applications that minify HTML containing attacker-controlled JSON data could therefore transform inert data into active markup. A crafted payload could execute script in the origin of the generated page. PatchesThe issue is fixed in:
The minifier now re-escapes less-than signs after JSON serialization, preserving the script element boundary. WorkaroundsUsers who cannot upgrade can disable JSON minification with:
Fixed in
59.0.0
References
Updated Sep 08, 2026 · Source: OSV.dev |
24.0.0
unknown
Dependencies (26)
+ 18 more
Changelog
Compare changes
|
|
23.0.0
unknown
1 CVE
CVE-2026-72925
GHSA-5qr2-v392-m9g8
Sep 08, 2026
SWC HTML minifier may allow script element breakout when minifying embedded JSON
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Impact
Before the patched versions, JSON serialization could convert escaped
less-than signs such as Applications that minify HTML containing attacker-controlled JSON data could therefore transform inert data into active markup. A crafted payload could execute script in the origin of the generated page. PatchesThe issue is fixed in:
The minifier now re-escapes less-than signs after JSON serialization, preserving the script element boundary. WorkaroundsUsers who cannot upgrade can disable JSON minification with:
Fixed in
59.0.0
References
Updated Sep 08, 2026 · Source: OSV.dev |
23.0.0
unknown
Dependencies (26)
+ 18 more
Changelog
Compare changes
|
|
22.0.0
unknown
1 CVE
CVE-2026-72925
GHSA-5qr2-v392-m9g8
Sep 08, 2026
SWC HTML minifier may allow script element breakout when minifying embedded JSON
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Impact
Before the patched versions, JSON serialization could convert escaped
less-than signs such as Applications that minify HTML containing attacker-controlled JSON data could therefore transform inert data into active markup. A crafted payload could execute script in the origin of the generated page. PatchesThe issue is fixed in:
The minifier now re-escapes less-than signs after JSON serialization, preserving the script element boundary. WorkaroundsUsers who cannot upgrade can disable JSON minification with:
Fixed in
59.0.0
References
Updated Sep 08, 2026 · Source: OSV.dev |
22.0.0
unknown
Dependencies (26)
+ 18 more
Changelog
Compare changes
|
|
21.0.0
unknown
1 CVE
CVE-2026-72925
GHSA-5qr2-v392-m9g8
Sep 08, 2026
SWC HTML minifier may allow script element breakout when minifying embedded JSON
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Impact
Before the patched versions, JSON serialization could convert escaped
less-than signs such as Applications that minify HTML containing attacker-controlled JSON data could therefore transform inert data into active markup. A crafted payload could execute script in the origin of the generated page. PatchesThe issue is fixed in:
The minifier now re-escapes less-than signs after JSON serialization, preserving the script element boundary. WorkaroundsUsers who cannot upgrade can disable JSON minification with:
Fixed in
59.0.0
References
Updated Sep 08, 2026 · Source: OSV.dev |
21.0.0
unknown
Dependencies (26)
+ 18 more
Changelog
Compare changes
|
|
20.0.0
unknown
1 CVE
CVE-2026-72925
GHSA-5qr2-v392-m9g8
Sep 08, 2026
SWC HTML minifier may allow script element breakout when minifying embedded JSON
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Impact
Before the patched versions, JSON serialization could convert escaped
less-than signs such as Applications that minify HTML containing attacker-controlled JSON data could therefore transform inert data into active markup. A crafted payload could execute script in the origin of the generated page. PatchesThe issue is fixed in:
The minifier now re-escapes less-than signs after JSON serialization, preserving the script element boundary. WorkaroundsUsers who cannot upgrade can disable JSON minification with:
Fixed in
59.0.0
References
Updated Sep 08, 2026 · Source: OSV.dev |
20.0.0
unknown
Dependencies (26)
+ 18 more
Changelog
Compare changes
|
|
19.0.0
unknown
1 CVE
CVE-2026-72925
GHSA-5qr2-v392-m9g8
Sep 08, 2026
SWC HTML minifier may allow script element breakout when minifying embedded JSON
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Impact
Before the patched versions, JSON serialization could convert escaped
less-than signs such as Applications that minify HTML containing attacker-controlled JSON data could therefore transform inert data into active markup. A crafted payload could execute script in the origin of the generated page. PatchesThe issue is fixed in:
The minifier now re-escapes less-than signs after JSON serialization, preserving the script element boundary. WorkaroundsUsers who cannot upgrade can disable JSON minification with:
Fixed in
59.0.0
References
Updated Sep 08, 2026 · Source: OSV.dev |
19.0.0
unknown
Dependencies (26)
+ 18 more
Changelog
Compare changes
|
|
18.0.0
unknown
1 CVE
CVE-2026-72925
GHSA-5qr2-v392-m9g8
Sep 08, 2026
SWC HTML minifier may allow script element breakout when minifying embedded JSON
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Impact
Before the patched versions, JSON serialization could convert escaped
less-than signs such as Applications that minify HTML containing attacker-controlled JSON data could therefore transform inert data into active markup. A crafted payload could execute script in the origin of the generated page. PatchesThe issue is fixed in:
The minifier now re-escapes less-than signs after JSON serialization, preserving the script element boundary. WorkaroundsUsers who cannot upgrade can disable JSON minification with:
Fixed in
59.0.0
References
Updated Sep 08, 2026 · Source: OSV.dev |
18.0.0
unknown
Dependencies (26)
+ 18 more
Changelog
Compare changes
|
|
17.0.0
unknown
1 CVE
CVE-2026-72925
GHSA-5qr2-v392-m9g8
Sep 08, 2026
SWC HTML minifier may allow script element breakout when minifying embedded JSON
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Impact
Before the patched versions, JSON serialization could convert escaped
less-than signs such as Applications that minify HTML containing attacker-controlled JSON data could therefore transform inert data into active markup. A crafted payload could execute script in the origin of the generated page. PatchesThe issue is fixed in:
The minifier now re-escapes less-than signs after JSON serialization, preserving the script element boundary. WorkaroundsUsers who cannot upgrade can disable JSON minification with:
Fixed in
59.0.0
References
Updated Sep 08, 2026 · Source: OSV.dev |
17.0.0
unknown
Dependencies (26)
+ 18 more
Changelog
Compare changes
|
|
16.0.0
unknown
1 CVE
CVE-2026-72925
GHSA-5qr2-v392-m9g8
Sep 08, 2026
SWC HTML minifier may allow script element breakout when minifying embedded JSON
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Impact
Before the patched versions, JSON serialization could convert escaped
less-than signs such as Applications that minify HTML containing attacker-controlled JSON data could therefore transform inert data into active markup. A crafted payload could execute script in the origin of the generated page. PatchesThe issue is fixed in:
The minifier now re-escapes less-than signs after JSON serialization, preserving the script element boundary. WorkaroundsUsers who cannot upgrade can disable JSON minification with:
Fixed in
59.0.0
References
Updated Sep 08, 2026 · Source: OSV.dev |
16.0.0
unknown
Dependencies (26)
+ 18 more
Changelog
Compare changes
|
|
15.0.0
unknown
1 CVE
CVE-2026-72925
GHSA-5qr2-v392-m9g8
Sep 08, 2026
SWC HTML minifier may allow script element breakout when minifying embedded JSON
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Impact
Before the patched versions, JSON serialization could convert escaped
less-than signs such as Applications that minify HTML containing attacker-controlled JSON data could therefore transform inert data into active markup. A crafted payload could execute script in the origin of the generated page. PatchesThe issue is fixed in:
The minifier now re-escapes less-than signs after JSON serialization, preserving the script element boundary. WorkaroundsUsers who cannot upgrade can disable JSON minification with:
Fixed in
59.0.0
References
Updated Sep 08, 2026 · Source: OSV.dev |
15.0.0
unknown
Dependencies (26)
+ 18 more
Changelog
Compare changes
|
|
14.0.0
unknown
1 CVE
CVE-2026-72925
GHSA-5qr2-v392-m9g8
Sep 08, 2026
SWC HTML minifier may allow script element breakout when minifying embedded JSON
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Impact
Before the patched versions, JSON serialization could convert escaped
less-than signs such as Applications that minify HTML containing attacker-controlled JSON data could therefore transform inert data into active markup. A crafted payload could execute script in the origin of the generated page. PatchesThe issue is fixed in:
The minifier now re-escapes less-than signs after JSON serialization, preserving the script element boundary. WorkaroundsUsers who cannot upgrade can disable JSON minification with:
Fixed in
59.0.0
References
Updated Sep 08, 2026 · Source: OSV.dev |
14.0.0
unknown
Dependencies (26)
+ 18 more
Changelog
Compare changes
|