THREAT OPS › Threat News › [GHSA] GHSA-5qr2-v392-m9g8 (medium) — SWC HTML minifier may allow script element breakout when minifying embedded JSON
[GHSA] GHSA-5qr2-v392-m9g8 (medium) — SWC HTML minifier may allow script element breakout when minifying embedded JSON
GHSA-5qr2-v392-m9g8 Severity: medium CVE: CVE-2026-72925
SWC HTML minifier may allow script element breakout when minifying embedded JSON
## Impact
`@swc/html` minifies JSON contained in `script` elements such as `application/json` and `application/ld+json` by parsing and serializing the JSON value.
Before the patched versions, JSON serialization could convert escaped less-than signs such as `
Indicators of compromise
- CVE-2026-72925cve
Original source: https://github.com/advisories/GHSA-5qr2-v392-m9g8