CVE-2026-55847 | allure-framework Allure up to 2.38.x ANSI Helper ansi.js AnsiToHtml statusMessage/statusTrace cross site scripting

SecurityVulns

A vulnerability was found in allure-framework Allure up to 2.38.x and classified as problematic. This issue affects the function AnsiToHtml of the file allure-generator/src/main/javascript/helpers/ansi.js of the component ANSI Helper. The manipulation of the argument statusMessage/statusTrace results in cross site scripting.

This vulnerability was named CVE-2026-55847. The attack may be performed from remote. There is no available exploit.

It is suggested to upgrade the affected component.VulDB Recent EntriesRead More