Impact
ansi2html 1.7.0a0 through 1.9.3 convert ANSI escape sequences into HTML. The OSC 8 hyperlink feature embeds URL metadata in the text, but the implementation in these versions does not validate or escape the URL target. An attacker who can control the ANSI stream can inject a malicious href that uses a javascript: scheme or breaks out of the attribute, causing arbitrary scripts to run when the converted HTML is displayed in a browser. This enables attackers to steal session data, hijack accounts, or perform other malicious actions in the victim’s browser context.
Affected Systems
The vulnerability affects the pycontribs ansi2html project. Users running ansi2html versions 1.7.0a0 through 1.9.3 are impacted. No other version ranges are listed as affected.
Risk and Exploitability
The CVSS base score is 5.3, indicating moderate severity. EPSS is not available, and the issue is not listed in CISA KEV, so no evidence of widespread exploitation is currently known. The likely attack vector requires an attacker to supply or influence ANSI text that the application converts; when the resulting HTML is rendered by a browser, the injected script executes with the user’s browser privileges.
OpenCVE Enrichment