CVE-2026-68747: CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') in rrrene html_sanitize_ex
CVE-2026-68747 is a low-severity injection vulnerability in the CSS scrubber of the rrrene html_sanitize_ex library. It allows an unauthenticated remote attacker to inject CSS at-rules, such as importing a remote stylesheet, into pages served to other users. The vulnerability arises because the scrubber applies its allowlist only to property:value patterns, leaving other CSS constructs like @import rules uninspected and thus injectable. The injected content remains confined within the <style> element and does not execute scripts. This issue affects versions 0.3.1 up to but not including 1.5.4.
AI Analysis
Technical Summary
The vulnerability in rrrene html_sanitize_ex's CSS scrubber (html_sanitize_ex.Scrubber.CSS.scrub/1) stems from improper neutralization of special elements in output used by downstream components, specifically allowing injection of CSS at-rules. The scrubber uses a Regex.replace to apply an allowlist only to substrings matching property:value declarations, so input not matching this pattern is copied unchanged. This enables injection of CSS at-rules like '@import url(//attacker.example/style.css);' which survive the sanitization. Element boundaries are resolved before the scrubber runs, preventing injected content from escaping the <style> element or executing scripts. The vulnerability affects versions from 0.3.1 before 1.5.4.
Potential Impact
An unauthenticated remote attacker can inject CSS at-rules into pages served to other users, potentially causing the inclusion of remote stylesheets. However, the injected content is confined within the <style> element and does not allow script execution. The CVSS 4.0 base score is 2.3, indicating low severity with limited impact.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. No official fix or temporary workaround is indicated in the provided data. Users should monitor vendor communications for updates and consider restricting or validating CSS input more strictly until a patch is available.
CVE-2026-68747: CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') in rrrene html_sanitize_ex
Description
CVE-2026-68747 is a low-severity injection vulnerability in the CSS scrubber of the rrrene html_sanitize_ex library. It allows an unauthenticated remote attacker to inject CSS at-rules, such as importing a remote stylesheet, into pages served to other users. The vulnerability arises because the scrubber applies its allowlist only to property:value patterns, leaving other CSS constructs like @import rules uninspected and thus injectable. The injected content remains confined within the <style> element and does not execute scripts. This issue affects versions 0.3.1 up to but not including 1.5.4.
CVSS v4.0
Score 2.3low
Affected software
cpe:2.3:a:rrrene:html_sanitize_ex:*:*:*:*:*:*:*:*Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in rrrene html_sanitize_ex's CSS scrubber (html_sanitize_ex.Scrubber.CSS.scrub/1) stems from improper neutralization of special elements in output used by downstream components, specifically allowing injection of CSS at-rules. The scrubber uses a Regex.replace to apply an allowlist only to substrings matching property:value declarations, so input not matching this pattern is copied unchanged. This enables injection of CSS at-rules like '@import url(//attacker.example/style.css);' which survive the sanitization. Element boundaries are resolved before the scrubber runs, preventing injected content from escaping the <style> element or executing scripts. The vulnerability affects versions from 0.3.1 before 1.5.4.
Potential Impact
An unauthenticated remote attacker can inject CSS at-rules into pages served to other users, potentially causing the inclusion of remote stylesheets. However, the injected content is confined within the <style> element and does not allow script execution. The CVSS 4.0 base score is 2.3, indicating low severity with limited impact.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. No official fix or temporary workaround is indicated in the provided data. Users should monitor vendor communications for updates and consider restricting or validating CSS input more strictly until a patch is available.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- EEF
- Date Reserved
- 2026-07-31T13:23:00.355Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a74ab42bf8831d539ec74eb
Added to database: 08/06/2026, 15:41:54 UTC
Last enriched: 08/06/2026, 15:57:44 UTC
Last updated: 08/06/2026, 16:06:49 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.