What is CVE-2026-72925?
CVE-2026-72925 is a vulnerability in SWC's HTML minifier JSON processing. In versions prior to @swc/html 1.15.47-nightly-20260729.1 and swc_html_minifier 59.0.0, parsing and serializing attacker-controlled JSON in application/json and application/ld+json script elements can lead to security issues. Affected users should update to the specified versions immediately.
Azərbaycanca: CVE-2026-72925 SWC-in HTML minifier komponentində JSON emalı zəifliyidir. @swc/html 1.15.47-nightly-20260729.1 və swc_html_minifier 59.0.0-dən əvvəlki versiyalarda, təcavüzkar tərəfindən idarə olunan JSON-un parse və serialize edilməsi təhlükəsizlik probleminə səbəb olur. Zərərçəkənlər dərhal qeyd olunan versiyalara yeniləmə etməlidir.
FAQ2
Which SWC component is affected by CVE-2026-72925?
CVE-2026-72925 is a vulnerability in the JSON processing of SWC's HTML minifier component.
Which versions should I update to in order to mitigate CVE-2026-72925?
Affected users should update to @swc/html 1.15.47-nightly-20260729.1 and swc_html_minifier 59.0.0.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.