Impact
This vulnerability involves the ansi.js helper in Allure 2, which transforms statusMessage and statusTrace into HTML via AnsiToHtml without sanitization and then wraps the output in Handlebars SafeString, effectively disabling auto‑escaping. When malicious test reports (JUnit, TRX, xUnit, etc.) supply crafted status messages or traces, the helper renders arbitrary JavaScript in the report. Because the output is treated as safe, any embedded script runs in the report’s origin, allowing an attacker to read or modify the page, exfiltrate data, or hijack the session. The flaw is a classic Stored XSS (CWE‑79) and was fixed in Allure 2 version 2.39.0.
Affected Systems
Allure Framework Allure 2: versions prior to 2.39.0 are impacted. The vulnerability appears in both the allure2 module and the allure-generator component managed by io.qameta.allure. Report generations that embed status messages or traces from JUnit, TRX, xUnit, xctest, Allure1, or Allure2 plugins can expose the flaw.
Risk and Exploitability
The flaw can only be exploited by an attacker who can inject malicious content into input files that allure‑generator processes (such as JUnit or TRX XML), which is usually done during test execution or report generation. When a victim opens the resulting Allure report in a browser, the unescaped markup executes as JavaScript in the report’s origin. The EPSS score is < 1 %, the CVSS score is 6.1, and the vulnerability is not in KEV, which together imply a moderate but low likelihood of real‑world exploitation. The risk is mitigated by applying the 2.39.0 or later release, which performs proper escaping.
OpenCVE Enrichment
Github GHSA