npm · @swc/html
SWC HTML minifier may allow script element breakout when minifying embedded JSON
@swc/html minifies JSON contained in script elements such as
application/json and application/ld+json by parsing and serializing the
JSON value.
Before the patched versions, JSON serialization could convert escaped
less-than signs such as \u003C into literal < characters. If the JSON
contained an escaped </script> sequence, the generated HTML could terminate
the containing script element early because HTML tokenization occurs before
the JSON is consumed.
Applications that minify HTML containing attacker-controlled JSON data could therefore transform inert data into active markup. A crafted payload could execute script in the origin of the generated page.
The issue is fixed in:
@swc/html 1.15.47swc_html_minifier 59.0.0The minifier now re-escapes less-than signs after JSON serialization, preserving the script element boundary.
Users who cannot upgrade can disable JSON minification with:
await minify(html, {
minifyJson: false,
});
Is your project exposed to this? Stateward checks every dependency on every pull request and flags it only if your code actually reaches it.
Check my repoSources: CISA KEV (public domain), OSV.dev & GitHub Advisory Database (CC-BY-4.0), FIRST EPSS, NVD/CWE (public domain). Served live from the Stateward advisory database.