CVE-2026-55847 Overview
CVE-2026-55847 is a stored cross-site scripting (XSS) vulnerability in Allure 2, the version 2.x branch of Allure Report. The flaw resides in the ansi.js helper at allure-generator/src/main/javascript/helpers/ansi.js, which passes attacker-influenced statusMessage and statusTrace values through AnsiToHtml without HTML escaping. The output is then wrapped in a Handlebars SafeString, disabling template auto-escaping in status-details.hbs. Affected versions are all releases prior to 2.39.0. The issue is classified under [CWE-79].
Critical Impact
When a user views a crafted test report, unescaped markup executes arbitrary JavaScript in the report origin, exposing report data and compromising sessions bound to that origin.
Affected Products
- Allure 2 (Allure Report 2.x) versions prior to 2.39.0
- JunitXmlPlugin, TRX, xUnit XML, and xctest input plugins
- Allure1 and Allure2 plugins consuming statusMessage and statusTrace fields
Discovery Timeline
- 2026-09-14 - CVE-2026-55847 published to NVD
- 2026-09-14 - Last updated in NVD database
Technical Details for CVE-2026-55847
Vulnerability Analysis
The vulnerability is a stored XSS in the Allure 2 report generator. The ansi.js helper converts ANSI escape sequences in test failure output to HTML for display in the rendered report. Because the helper wraps the converted output in a Handlebars SafeString, the templating engine skips its default HTML escaping when rendering the status details block. Any HTML or <script> payload embedded in the source test output flows through to the DOM verbatim.
Attackers can plant payloads by supplying crafted JUnit XML failure messages and traces that JunitXmlPlugin.java populates directly into statusMessage and statusTrace. Equivalent input paths exist in the TRX, xUnit XML, xctest, Allure1, and Allure2 plugins. Any viewer that opens the generated report executes the injected script in the report's origin, exposing test artifacts and any authenticated session tied to that origin.
Root Cause
The root cause is missing output encoding combined with an explicit opt-out of Handlebars auto-escaping. The ansi.js helper concatenates converted ANSI-to-HTML output with unsanitized user-controlled text and returns a SafeString, which instructs Handlebars to skip escaping. This is an incomplete-fix case: pull request 3271 addressed link helpers but did not remediate the ANSI helper path.
Attack Vector
Exploitation requires an attacker to influence the input consumed by an Allure report build, such as a JUnit XML file produced during CI. The attacker embeds JavaScript inside a failure message or stack trace field. When the generated static report is later opened in a browser, the payload executes with the privileges of the report origin, enabling data exfiltration and session compromise for co-hosted applications.
// Patch excerpt: Allure1Plugin.java imports the HtmlSanitizerUtils helper
// introduced to sanitize descriptionHtml and related fields.
import io.qameta.allure.entity.Step;
import io.qameta.allure.entity.TestResult;
import io.qameta.allure.entity.Time;
import io.qameta.allure.util.HtmlSanitizerUtils;
import org.allurefw.allure1.AllureUtils;
import org.slf4j.Logger;
import org.slf4j.LoggerFactory;
Source: GitHub Commit 1c56939
Detection Methods for CVE-2026-55847
Indicators of Compromise
- JUnit, TRX, xUnit, or xctest XML files whose message or stack trace attributes contain <script>, <img onerror=, javascript: URIs, or other HTML control characters.
- Generated Allure report data/test-cases/*.json entries whose statusMessage or statusTrace contain raw HTML tags.
- Outbound HTTP requests from browsers viewing Allure reports to unexpected external hosts, indicating payload callback activity.
Detection Strategies
- Scan CI-produced test result artifacts for HTML tags or ANSI-wrapped script content before publishing reports.
- Compare the Allure generator version in build pipelines against 2.39.0 and flag builds using earlier releases.
- Review web server access logs for the Allure report origin for anomalous fetches of data/test-cases/ JSON followed by requests to attacker-controlled domains.
Monitoring Recommendations
- Instrument the browser origin hosting Allure reports with a strict Content Security Policy and log CSP violation reports.
- Alert on modifications to files under allure-generator/src/main/javascript/helpers/ in forks or vendored copies of Allure 2.
- Track test-result ingestion jobs that produce unusually large statusMessage or statusTrace fields for further review.
How to Mitigate CVE-2026-55847
Immediate Actions Required
- Upgrade Allure 2 to version 2.39.0 or later in all report-generation pipelines.
- Rotate any session tokens or credentials that could have been exposed to users viewing reports produced by vulnerable versions.
- Audit historical reports on shared hosting for embedded HTML in status details and remove or regenerate affected artifacts.
Patch Information
The fix is delivered in Allure 2 release 2.39.0 via pull request 3296 and commit 1c5693933f519e64379f1a14eb3c7beeba7bc7cd. The patch adds jsoup as a dependency, introduces HtmlSanitizerUtils, sanitizes descriptionHtml, and adds escaping to the ANSI helper. Details are available in the GitHub Security Advisory GHSA-gx93-m64w-5m6h, Pull Request #3296, and the Release Notes for 2.39.0.
Workarounds
- Host Allure reports on a dedicated origin with no shared cookies or session storage to limit the blast radius of executed script.
- Apply a strict Content Security Policy (for example, script-src 'self') to the report host to block inline injected scripts.
- Pre-process test result XML in CI to strip HTML tags and ANSI escape sequences from failure messages and traces before invoking the Allure generator.
# Example: enforce Allure 2 >= 2.39.0 in a Gradle build
./gradlew dependencies --configuration runtimeClasspath \
| grep -E 'io\.qameta\.allure' \
| awk '{print $NF}'
# Fail the build if an older version is present
allure --version | awk '{print $2}' | \
awk -F. '{ if ($1<2 || ($1==2 && $2<39)) { print "Upgrade Allure to 2.39.0+"; exit 1 } }'
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.