CVE-2026-55847: Allure Unsanitized Description Html
HTML content is assigned to the report object model without sanitization. This directly causes Stored XSS when the Allure report is generated and viewed on the frontend. Ensure the content is passed through an HTML sanitizer such as `HtmlSanitizerUtils.sanitizeHtml()` before assignment.
greprules fetch cve-2026-55847-allure-unsanitized-description-html --engine opengrepDescription
HTML content is assigned to the report object model without sanitization. This directly causes Stored XSS when the Allure report is generated and viewed on the frontend. Ensure the content is passed through an HTML sanitizer such as `HtmlSanitizerUtils.sanitizeHtml()` before assignment.
Community feedback
0 rule-level signals from signed-in users.
- Useful reports
- 0
- Context false positives
- 0
- Metadata suggestions
- 0
Contextual precision
Aggregated from approved scan feedback. False-positive reports describe observed scan contexts, not a global rule verdict.
- Findings observed
- 0
- Projects
- 0
- Reporters
- 0
Precision details are collecting more signed-in reports before verdict counts or ratios are emphasized.
No approved finding verdicts yet.
No scan diagnostics reported yet.