CVE-2026-5090

Template::Plugin::HTML versions through 3.102 for Perl allows HTML and JavaScript to be injected. The html_filter function did not escape single quotes. HTML attributes inside of single quotes could be have code injected. For example, the variable "var" in <a id='ref' title='[% var | html %]'> would not be properly escaped. An attacker could insert some limited HTML and JavaScript, for example, var = " ' onclick='while (true) { alert(1) }'" Note that arbitrary HTML and JavaScript would be difficult to inject, because angle brackets, ampersands and double-quotes would still be escaped.
Configurations

No configuration.

History

24 Jul 2026, 09:10

Type Values Removed Values Added
Summary
  • (es) Las versiones de Template::Plugin::HTML hasta la 3.102 para Perl permiten la inyección de HTML y JavaScript. La función html_filter no escapaba las comillas simples. Los atributos HTML dentro de comillas simples podrían ser objeto de inyección de código. Por ejemplo, la variable 'var' en <a id='ref' title='[% var | html %]'> no se escaparía correctamente. Un atacante podría insertar algo de HTML y JavaScript limitado, por ejemplo, var = " ' onclick='while (true) { alert(1) }'" Tenga en cuenta que sería difícil inyectar HTML y JavaScript arbitrarios, porque los corchetes angulares, los ampersands y las comillas dobles seguirían siendo escapados.

20 May 2026, 14:17

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1

20 May 2026, 00:16

Type Values Removed Values Added
References
  • () http://www.openwall.com/lists/oss-security/2026/05/19/40 -

19 May 2026, 22:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-19 22:16

Updated : 2026-07-24 09:10


NVD link : CVE-2026-5090

Mitre link : CVE-2026-5090

CVE.ORG link : CVE-2026-5090


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')