#1148327 python-ansi2html: CVE-2026-92973

Package:
src:python-ansi2html
Source:
src:python-ansi2html
Submitter:
Salvatore Bonaccorso
Date:
2026-09-18 19:15:02 UTC
Severity:
normal
Tags:
#1148327#5
Date:
2026-09-18 18:36:44 UTC
From:
To:
Hi,

The following vulnerability was published for python-ansi2html.

CVE-2026-92973[0]:
| ansi2html versions 1.7.0a0 through 1.9.3 contain a cross-site
| scripting vulnerability in OSC 8 hyperlink handling that fails to
| validate or escape URL targets. Attackers controlling ANSI text
| input can inject javascript: schemes or terminate href attributes to
| execute arbitrary scripts in the context of pages displaying
| converted output.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-92973
https://www.cve.org/CVERecord?id=CVE-2026-92973
[1] https://github.com/pycontribs/ansi2html/commit/89d1c231c60ac52005f3b21bbba551c786c554fc

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

#1148327#10
Date:
2026-09-18 19:13:48 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
python-ansi2html, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1148327@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Alexandre Detiste <tchet@debian.org> (supplier of updated python-ansi2html package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Fri, 18 Sep 2026 20:43:42 +0200
Source: python-ansi2html
Architecture: source
Version: 1.9.5-1
Distribution: unstable
Urgency: medium
Maintainer: Debian Python Team <team+python@tracker.debian.org>
Changed-By: Alexandre Detiste <tchet@debian.org>
Closes: 1148327
Changes:
 python-ansi2html (1.9.5-1) unstable; urgency=medium
 .
   * New upstream version 1.9.5 (Closes: #1148327)
     - CVE-2026-92973: ansi2html versions 1.7.0a0 through 1.9.3 contain
                       a cross-site scripting vulnerability
   * Refresh rename_cli.patch
Checksums-Sha1:
 f697b49aa81e8101d8529dadbfb8fbd2bf4660b1 2200 python-ansi2html_1.9.5-1.dsc
 a2a28a6ba2320a30182d1c83a1d748ad5d6b6670 40646 python-ansi2html_1.9.5.orig.tar.gz
 fcae3e8fc4d6bb4e844dd091002256cdb5604a95 2948 python-ansi2html_1.9.5-1.debian.tar.xz
 2b6ba422ba52c8070b27b59f6ea89fd7bb9583d7 6996 python-ansi2html_1.9.5-1_source.buildinfo
Checksums-Sha256:
 027faa03f04e31673e72c4b9e9b57f58c63aff9763ed3df9c5af68e125da79da 2200 python-ansi2html_1.9.5-1.dsc
 2a32eb8bf4e868ce35a2f213a4170907273675214a8876c115de7ce20174c101 40646 python-ansi2html_1.9.5.orig.tar.gz
 df1e784ecf4b3819f38e5fc58ae5926611a0fe5f958fa1588d4d4b32fba0167f 2948 python-ansi2html_1.9.5-1.debian.tar.xz
 86763d62dd22c8cd6613282fc21f2c1d11c4a394131690466e52f199c09b7c06 6996 python-ansi2html_1.9.5-1_source.buildinfo
Files:
 4d669c797c067f260d8fc077b65a100e 2200 python optional python-ansi2html_1.9.5-1.dsc
 a6d8d4598b58cf238173cafe5c5e8d9d 40646 python optional python-ansi2html_1.9.5.orig.tar.gz
 5cdbf6dd938b7f771a6ad8208fd6260e 2948 python optional python-ansi2html_1.9.5-1.debian.tar.xz
 36c403829c5b5ef3536708cfc33ed05e 6996 python optional python-ansi2html_1.9.5-1_source.buildinfo
-----BEGIN PGP SIGNATURE-----

iQJFBAEBCgAvFiEEj23hBDd/OxHnQXSHMfMURUShdBoFAmqth3ERHHRjaGV0QGRl
Ymlhbi5vcmcACgkQMfMURUShdBqmDA//bGqHeHcDbmZydpTaQTwUZD2S8BGcpX+C
E626M54gHAWS7Jxfrx+49js+zuDjto/CfNIOJZZpaGLVMzeFNUzbmdOsaP2nQhu0
FOUNP+l/BFQROvxo70tPVOU/3XC/qDlvcmTwHB+zGlQ26rCefSWjv0n0D8P+yhXu
ngNdvFWzo5+Lf/ijGRTMCtIS09HwYkodzKbjiPUqB+86gL1CjCKpYdgCvEg73vmj
N5gDDgO2xJXGun4m7FdVmYt26v1kuTukId4cX8Z6exlSu7AqpAulV1lX038Rl2Vu
1EHsX2y0/ZzoLFtVrhQ3bRc06HoCUDdEfX/LNF81xc4CTyGIodvjreAZBaWRCTQL
5zuv5+L2DwDn30yjsoEJjAAS4iFO7FJEnxqDwlUFb3Nt5zknhSclJ+UfOspQ+FCG
l+0HZd75Soc3BvDx6PHx7kLUernSMVOOJybsHNtuB9rZeBpMbnsL3GnK5vw1s6ah
QYCWquAxqwlNforKxRdN0uVL0NA+o+S3U9c/d6ygtECOYH9h90tm+dWyPuVEu4sF
cqAIQUwTjbsrid2vNkQHGW4rLN6HJiLhyeuIqBzX/bk9CtHNX07Ocd/fRVo4GPfY
Gj3vs4BynxzhI/27Qul/6RJt7k+pP00NBr1rxahpaKmeshfw+0l74QZZlfNjcPvD
HyB8C/wS8Mo=
=YHva
-----END PGP SIGNATURE-----