Executive brief
AngleSharp is a library used by developers to parse and process HTML content, often for security sanitization. A flaw in how it handles specific MathML elements allows malicious code to be hidden in a way that AngleSharp ignores but web browsers will execute. This could allow an attacker to bypass security filters and perform cross-site scripting (XSS) attacks, potentially leading to unauthorized actions or data theft.
Technical details
AngleSharp fails to comply with the HTML5 specification regarding MathML <annotation-xml> elements with specific encoding attributes (text/html or application/xhtml+xml). Specifically, the MathAnnotationXmlElement is missing the HtmlTip flag, causing the parser to route tokens to the foreign parser instead of the HTML parser. Additionally, HtmlMarkupFormatter.WriteAttributeValue() fails to escape '<' and '>' characters in attribute values. These combined issues allow an attacker to craft a payload that AngleSharp parses as a harmless attribute but which, when serialized and re-parsed by a browser, executes as malicious script (mXSS). This bypasses HTML sanitizers that rely on AngleSharp's DOM representation. Fixed in version 1.5.0.
Affected products
- AngleSharp AngleSharp < 1.5.0
Timeline
- 2026-06-06: disclosed
- 2026-07-17: advisory
- 2026-07-17: patched: Version 1.5.0 released
References
- https://api.github.com/users/internetpestcontrol
- https://github.com/internetpestcontrol
- https://api.github.com/users/internetpestcontrol/gists%7B/gist_id%7D
- https://api.github.com/users/internetpestcontrol/repos
- https://avatars.githubusercontent.com/u/267571516?v=4
- https://api.github.com/users/internetpestcontrol/events%7B/privacy%7D