{"id":"CVE-2020-26293","aliases":["GHSA-8j9v-h2vp-2hhv"],"url":"https://o3.security/vulnerability/CVE-2020-26293","summary":"XSS in HtmlSanitizer","details":"HtmlSanitizer is a .NET library for cleaning HTML fragments and documents from constructs that can lead to XSS attacks. In HtmlSanitizer before version 5.0.372, there is a possible XSS bypass if style tag is allowed. If you have explicitly allowed the `<style>` tag, an attacker could craft HTML that includes script after passing through the sanitizer. The default settings disallow the `<style>` tag so there is no risk if you have not explicitly allowed the `<style>` tag. The problem has been fixed in version 5.0.372.","published":"2021-01-04T19:15:14.970Z","modified":"2026-07-09T01:07:38.108608Z","cvss":{"score":6.1,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"},"epss":{"score":0.00997,"percentile":0.59612,"asOf":"2026-08-23"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"NuGet","name":"HtmlSanitizer","fixedVersion":"5.0.372"}],"fix":{"url":"https://github.com/mganss/HtmlSanitizer/commit/a3a7602a44d4155d51ec0fbbedc2a49e9c7e2eb8","label":"mganss/HtmlSanitizer@a3a7602"},"references":[{"type":"ADVISORY","url":"https://github.com/mganss/HtmlSanitizer/releases/tag/v5.0.372"},{"type":"ADVISORY","url":"https://github.com/mganss/HtmlSanitizer/security/advisories/GHSA-8j9v-h2vp-2hhv"},{"type":"ADVISORY","url":"https://www.nuget.org/packages/HtmlSanitizer/"},{"type":"FIX","url":"https://github.com/mganss/HtmlSanitizer/commit/a3a7602a44d4155d51ec0fbbedc2a49e9c7e2eb8"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-09T01:07:38.108608Z"}}