SWC HTML minifier may allow script element breakout when minifying embedded JSON
GHSA-5qr2-v392-m9g8 · CVE-2026-72925
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
Impact
@swc/html minifies JSON contained in script elements such asapplication/json and application/ld+json by parsing and serializing the
JSON value.
Before the patched versions, JSON serialization could convert escaped
less-than signs such as \u003C into literal < characters. If the JSON
contained an escaped </script> sequence, the generated HTML could terminate
the containing script element early because HTML tokenization occurs before
the JSON is consumed.
Applications that minify HTML containing attacker-controlled JSON data could
therefore transform inert data into active markup. A crafted payload could
execute script in the origin of the generated page.
Patches
The issue is fixed in:
@swc/html1.15.47swc_html_minifier59.0.0
The minifier now re-escapes less-than signs after JSON serialization, preserving
the script element boundary.
Workarounds
Users who cannot upgrade can disable JSON minification with:
await minify(html, {
minifyJson: false,
});
References
- WEB https://github.com/swc-project/swc/security/advisories/GHSA-5qr2-v392-m9g8
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2026-72925
- WEB https://github.com/swc-project/swc/pull/12080
- WEB https://github.com/swc-project/swc/commit/e1877b44bdac8abc9fd51e984d584f40f6999832
- PACKAGE https://github.com/swc-project/swc
- WEB https://github.com/swc-project/swc/releases/tag/v1.15.47
- WEB https://github.com/swc-project/swc/releases/tag/v1.15.47-nightly-20260729.1
Ready to move
Start Securing
Free, no credit card | First findings in minutes