Description
Allure 2 is the version 2.x branch of Allure Report, a multi-language test reporting tool. Prior to 2.39.0, the ansi.js helper at allure-generator/src/main/javascript/helpers/ansi.js passes attacker-influenced statusMessage and statusTrace values through AnsiToHtml without HTML escaping and wraps the result in Handlebars SafeString, disabling template auto-escaping in allure-generator/src/main/javascript/blocks/status-details/status-details.hbs. JunitXmlPlugin.java can populate these fields directly from crafted JUnit XML failure messages and traces, and equivalent input flows exist in the TRX, xUnit XML, xctest, and Allure1 and Allure2 plugins. When a user views the affected status details, unescaped markup executes arbitrary JavaScript in the report origin, which can expose report data and compromise sessions associated with that origin. This is an incomplete-fix case because PR 3271 escaped link helpers but did not address the ANSI helper. This issue is fixed in version 2.39.0.
Published: 2026-09-14
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Stored XSS in Allure Reports
Action: Immediate Patch
AI Analysis

Impact

This vulnerability involves the ansi.js helper in Allure 2, which transforms statusMessage and statusTrace into HTML via AnsiToHtml without sanitization and then wraps the output in Handlebars SafeString, effectively disabling auto‑escaping. When malicious test reports (JUnit, TRX, xUnit, etc.) supply crafted status messages or traces, the helper renders arbitrary JavaScript in the report. Because the output is treated as safe, any embedded script runs in the report’s origin, allowing an attacker to read or modify the page, exfiltrate data, or hijack the session. The flaw is a classic Stored XSS (CWE‑79) and was fixed in Allure 2 version 2.39.0.

Affected Systems

Allure Framework Allure 2: versions prior to 2.39.0 are impacted. The vulnerability appears in both the allure2 module and the allure-generator component managed by io.qameta.allure. Report generations that embed status messages or traces from JUnit, TRX, xUnit, xctest, Allure1, or Allure2 plugins can expose the flaw.

Risk and Exploitability

The flaw can only be exploited by an attacker who can inject malicious content into input files that allure‑generator processes (such as JUnit or TRX XML), which is usually done during test execution or report generation. When a victim opens the resulting Allure report in a browser, the unescaped markup executes as JavaScript in the report’s origin. The EPSS score is < 1 %, the CVSS score is 6.1, and the vulnerability is not in KEV, which together imply a moderate but low likelihood of real‑world exploitation. The risk is mitigated by applying the 2.39.0 or later release, which performs proper escaping.

Generated by OpenCVE AI on September 20, 2026 at 23:10 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Allure to version 2.39.0 or later, which implements proper escaping of status messages and traces.
  • If an upgrade is not possible, sanitize the statusMessage and statusTrace inputs in the test reports, or disable plugins that inject these fields from external XML sources.
  • Deploy the generated reports behind a subdomain with a strict Content Security Policy that disallows inline scripting and restricts script execution to trusted sources.

Generated by OpenCVE AI on September 20, 2026 at 23:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-gx93-m64w-5m6h Allure Report: Stored XSS via unescaped ANSI helper in status message/trace rendering
History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Allure-framework
Allure-framework allure-generator
Allure-framework allure2
Vendors & Products Allure-framework
Allure-framework allure-generator
Allure-framework allure2

Mon, 14 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description Allure 2 is the version 2.x branch of Allure Report, a multi-language test reporting tool. Prior to 2.39.0, the ansi.js helper at allure-generator/src/main/javascript/helpers/ansi.js passes attacker-influenced statusMessage and statusTrace values through AnsiToHtml without HTML escaping and wraps the result in Handlebars SafeString, disabling template auto-escaping in allure-generator/src/main/javascript/blocks/status-details/status-details.hbs. JunitXmlPlugin.java can populate these fields directly from crafted JUnit XML failure messages and traces, and equivalent input flows exist in the TRX, xUnit XML, xctest, and Allure1 and Allure2 plugins. When a user views the affected status details, unescaped markup executes arbitrary JavaScript in the report origin, which can expose report data and compromise sessions associated with that origin. This is an incomplete-fix case because PR 3271 escaped link helpers but did not address the ANSI helper. This issue is fixed in version 2.39.0.
Title Allure: Stored XSS via unescaped ANSI helper in Allure report status message/trace rendering
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

Allure-framework Allure-generator Allure2
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-14T20:06:08.065Z

Reserved: 2026-06-17T16:29:38.865Z

Link: CVE-2026-55847

cve-icon Vulnrichment

Updated: 2026-09-14T19:20:50.390Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-14T18:17:55.990

Modified: 2026-09-30T17:43:24.057

Link: CVE-2026-55847

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T23:15:04Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')