CVE-2026-92973:
ansi2html versions 1.7.0a0 through 1.9.3 contain a cross-site scripting vulnerability in OSC 8 hyperlink handling that fails to validate or escape URL targets. Attackers controlling ANSI text input can inject javascript: schemes or terminate href attributes to execute arbitrary scripts in the context of pages displaying converted output.
CVE-2026-92973:
ansi2html versions 1.7.0a0 through 1.9.3 contain a cross-site scripting vulnerability in OSC 8 hyperlink handling that fails to validate or escape URL targets. Attackers controlling ANSI text input can inject javascript: schemes or terminate href attributes to execute arbitrary scripts in the context of pages displaying converted output.
debian/patches: 1 patch with invalid metadata
high
Among the 1 debian patch
available in version 1.9.2-2 of the package,
we noticed the following issues:
1 patch with
invalid metadata that ought to be fixed.
Standards version of the package is outdated.
wishlist
The package should be updated to follow the last version of Debian Policy
(Standards-Version 4.7.4 instead of
4.7.3).
Migration status for python-ansi2html (1.9.2-2 to 1.9.5-1): Waiting for test results or another package, or too young (no action required now - check later)