CVE-2026-55847: Allure Unsanitized Description Html

HTML content is assigned to the report object model without sanitization. This directly causes Stored XSS when the Allure report is generated and viewed on the frontend. Ensure the content is passed through an HTML sanitizer such as `HtmlSanitizerUtils.sanitizeHtml()` before assignment.

Provally CuratedPublic repositoryMediumMedium confidenceVerifiedApache-2.0Java
greprules fetch cve-2026-55847-allure-unsanitized-description-html --engine opengrep

Description

HTML content is assigned to the report object model without sanitization. This directly causes Stored XSS when the Allure report is generated and viewed on the frontend. Ensure the content is passed through an HTML sanitizer such as `HtmlSanitizerUtils.sanitizeHtml()` before assignment.