PT-2026-32988 · Hackage · Hackage-Server

Published

2026-03-28

·

Updated

2026-04-23

·

CVE-2026-40472

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions hackage-server versions prior to 2de3ae45082f8f3f29a41f6aff620d09d0e74058
Description User-controlled metadata from .cabal files are rendered into HTML 'href' attributes without proper sanitization, enabling stored Cross-Site Scripting (XSS), which is a technique where malicious scripts are injected into trusted websites. The affected fields include homepage, bug-reports, source-repository.location, and description (Haddock hyperlinks).
Recommendations Update to commit 2de3ae45082f8f3f29a41f6aff620d09d0e74058 or later.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2026-40472
HSEC-2026-0004

Affected Products

Hackage-Server