CVE-2026-55847
Last modified
CVE-2026-55847 is a medium-severity vulnerability rated 6.1/10 on the CVSS scale. Allure 2 is the version 2.x branch of Allure Report, a multi-language test reporting tool. Prior to 2.39.0, the ansi.js helper at allure-generator/src/main/javascript/helpers/ansi.js passes attacker-influenced statusMessage and statusTrace values through AnsiToHtml without HTML escaping and wraps the result in Handlebars SafeString, disabling template auto-escaping in allure-generator/src/main/javascript/blocks/status-details/status-details.hbs.
Description
Allure 2 is the version 2.x branch of Allure Report, a multi-language test reporting tool. Prior to 2.39.0, the ansi.js helper at allure-generator/src/main/javascript/helpers/ansi.js passes attacker-influenced statusMessage and statusTrace values through AnsiToHtml without HTML escaping and wraps the result in Handlebars SafeString, disabling template auto-escaping in allure-generator/src/main/javascript/blocks/status-details/status-details.hbs. JunitXmlPlugin.java can populate these fields directly from crafted JUnit XML failure messages and traces, and equivalent input flows exist in the TRX, xUnit XML, xctest, and Allure1 and Allure2 plugins. When a user views the affected status details, unescaped markup executes arbitrary JavaScript in the report origin, which can expose report data and compromise sessions associated with that origin. This is an incomplete-fix case because PR 3271 escaped link helpers but did not address the ANSI helper. This issue is fixed in version 2.39.0.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| allure-framework | allure2 | < 2.39.0 |
| io.qameta.allure | allure-generator | < 2.39.0 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-55847?
How severe is CVE-2026-55847?
How do I fix CVE-2026-55847?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-55839Kestra is an open-source, event-driven orchestration platfor…8.7
- CVE-2026-5584A vulnerability has been found in Fosowl agenticSeek 0.1.0. …9.8
- CVE-2026-55841Graylog is a free and open log management platform. Prior to…7.5
- CVE-2026-55843Snipe-IT is an IT asset/license management system. Prior to …6.5
- CVE-2026-55844Home Assistant is open source home automation software that …7.5
- CVE-2026-55846Allure 2 is the version 2.x branch of Allure Report, a multi…6.2
- CVE-2026-55848mapfish-print is a component of MapFish for printing templat…8.6
- CVE-2026-55849@cyclonedx/cyclonedx-npm creates CycloneDX Software Bill of …8.5
- CVE-2026-5585A vulnerability was found in Tencent AI-Infra-Guard 4.0. The…7.5
- CVE-2026-55850Element Web is a Matrix web client built using the Matrix Re…5.3
- CVE-2026-55851Netty is a network application framework for development of …7.5
- CVE-2026-55852Frappe is a full-stack web application framework. Prior to 1…8.6
Are you affected by CVE-2026-55847?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
