Hi SRMers,
This is too late for 13.7, but please consider it for 13.8.
libtemplate-perl in trixie is affected by CVE-2026-5090 which we
marked no-dsa. The html_filter function did not escape single quotes,
allowing limited HTML or JavaScript to be injected.
The update cherry-picks the upstream commit including tests for the
problem. Additionally the update has been tested on debusine with
autopkgtests run for the reverse dependencies:
https://debusine.debian.net/debian/developers/work-request/1232282/
Can you accept it for 13.8?
Regards,
Salvatore