Junglewise Threat Intelligence

CVE-2026-54570: AngleSharp mXSS via annotation-xml HTML Integration Point Bypass

CVE-2026-54570 · Severity: medium · CVSS 6.9 · Published 2026-07-17

Vendors: NuGet.

Executive brief

AngleSharp is a library used by developers to parse and process HTML content, often for security sanitization. A flaw in how it handles specific MathML elements allows malicious code to be hidden in a way that AngleSharp ignores but web browsers will execute. This could allow an attacker to bypass security filters and perform cross-site scripting (XSS) attacks, potentially leading to unauthorized actions or data theft.

Technical details

AngleSharp fails to comply with the HTML5 specification regarding MathML <annotation-xml> elements with specific encoding attributes (text/html or application/xhtml+xml). Specifically, the MathAnnotationXmlElement is missing the HtmlTip flag, causing the parser to route tokens to the foreign parser instead of the HTML parser. Additionally, HtmlMarkupFormatter.WriteAttributeValue() fails to escape '<' and '>' characters in attribute values. These combined issues allow an attacker to craft a payload that AngleSharp parses as a harmless attribute but which, when serialized and re-parsed by a browser, executes as malicious script (mXSS). This bypasses HTML sanitizers that rely on AngleSharp's DOM representation. Fixed in version 1.5.0.

Affected products

  • AngleSharp AngleSharp < 1.5.0

Timeline

  • 2026-06-06: disclosed
  • 2026-07-17: advisory
  • 2026-07-17: patched: Version 1.5.0 released

References