CVE-2026-55847 | allure-framework Allure up to 2.38.x ANSI Helper ansi.js AnsiToHtml statusMessage/statusTrace cross site scripting
A vulnerability was found in allure-framework Allure up to 2.38.x and classified as problematic. This issue affects the function AnsiToHtml of the file allure-generator/src/main/javascript/helpers/ansi.js of the component ANSI Helper. The manipulation of the argument statusMessage/statusTrace results in cross site scripting.
This vulnerability was named CVE-2026-55847. The attack may be performed from remote. There is no available exploit.
It is suggested to upgrade the affected component.VulDB Recent EntriesRead More