CVE-2026-42539: Insufficient Xss Escaping In Attribute

Using basic HTML escaping (e.g., `escapeHtml`) inside HTML attributes is potentially insecure because it may not escape quotes (`"` or `'`). This allows an attacker to break out of the attribute and inject an event handler (Stored XSS). Use a robust sanitizer such as `DOMPurify` or `xss` (`filterXSS`), or ensure your escaping utility explicitly replaces quot

Provally CuratedPublic repositoryMediumMedium confidenceVerifiedApache-2.0JS
greprules fetch cve-2026-42539-insufficient-xss-escaping-in-attribute --engine opengrep

Description

Using basic HTML escaping (e.g., `escapeHtml`) inside HTML attributes is potentially insecure because it may not escape quotes (`"` or `'`). This allows an attacker to break out of the attribute and inject an event handler (Stored XSS). Use a robust sanitizer such as `DOMPurify` or `xss` (`filterXSS`), or ensure your escaping utility explicitly replaces quot