Back

MEDIUM

SWC HTML minifier may allow script element breakout when minifying embedded JSON

Published Aug 11, 2026

Description

SWC is a TypeScript / JavaScript compiler written in Rust. Prior to @swc/html 1.15.47-nightly-20260729.1 and swc_html_minifier 59.0.0, the minifyJson processing in crates/swc_html_minifier/src/lib.rs parsed and serialized attacker-controlled JSON in application/json and application/ld+json script elements without the escape_json_for_html_script behavior to re-escape less-than signs, allowing a closing script sequence to terminate the element early and execute script in the generated page's origin. This issue is fixed in @swc/html 1.15.47-nightly-20260729.1 and swc_html_minifier 59.0.0.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Aug 11, 2026
Updated Aug 11, 2026
Reserved Aug 10, 2026
CISA Vulnrichment
Updated Aug 11, 2026
NVD
Status Awaiting Analysis
Modified Sep 18, 2026
Red Hat
Severity n/a
Public date n/a
GHSA-5QR2-V392-M9G8