THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-5qr2-v392-m9g8 (medium) — SWC HTML minifier may allow script element breakout when minifying embedded JSON

[GHSA] GHSA-5qr2-v392-m9g8 (medium) — SWC HTML minifier may allow script element breakout when minifying embedded JSON

medgithub_advisoriesPublished 2026-09-08

GHSA-5qr2-v392-m9g8 Severity: medium CVE: CVE-2026-72925

SWC HTML minifier may allow script element breakout when minifying embedded JSON

## Impact

`@swc/html` minifies JSON contained in `script` elements such as `application/json` and `application/ld+json` by parsing and serializing the JSON value.

Before the patched versions, JSON serialization could convert escaped less-than signs such as `

Indicators of compromise

Original source: https://github.com/advisories/GHSA-5qr2-v392-m9g8