CVE 9.9 CRITICAL

Hackage package metadata stored XSS vulnerability_CVE-2026-40472

9.9 / 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L

Description

In hackage-server, user-controlled metadata from .cabal files are rendered into HTML
href attributes without proper sanitization, enabling stored
Cross-Site Scripting (XSS) attacks.

AI Analysis

Stored Cross-Site Scripting (XSS) vulnerability in hackage-server due to improper sanitization of user-controlled metadata from .cabal files

Basic Information

ID CVE-2026-40472
Source redhat-cnalr
Published Apr 23, 2026 at 15:00

Affected Product

Vendor Haskell
Product hackage-server
Version 0.1
Affected Versions 0.1

CWE Classification

AI Assessment

AI Score 9.9 / 10
AI Severity Critical
Vendor Haskell
Product hackage-server
Version 0.1

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.