@swc/html minifies JSON contained in script elements such as application/json and application/ld+json by parsing and serializing the JSON value.
Before the patched versions, JSON serialization could convert escaped less-than signs such as \u003C into literal sequence, the generated HTML could terminate the containing script element early because HTML tokenization occurs before the JSON is consumed.
Applications that minify HTML containing attacker-controlled JSON data could therefore transform inert data into active markup. A crafted payload could execute script in the origin of the generated page.
// patchesThe issue is fixed in:
- @swc/html 1.15.47
- swchtmlminifier 59.0.0
The minifier now re-escapes less-than signs after JSON serialization, preserving the script element boundary.
// workaroundsUsers who cannot upgrade can disable JSON minification with:
await minify(html, {
minifyJson: false,
});CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- Attack vector
- Network
- Attack complexity
- Low
- Privileges required
- None
- User interaction
- Required
- Scope
- Changed
- Confidentiality
- Low
- Integrity
- Low
- Availability
- None