CVE-2026-40470 Details
Description
A critical XSS vulnerability affected hackage-server and hackage.haskell.org. HTML and JavaScript files provided in source packages or via the documentation upload facility were served as-is on the main hackage.haskell.org domain. As a consequence, when a user with latent HTTP credentials browses to the package pages or documentation uploaded by a malicious package maintainer, their session can be hijacked to upload packages or documentation, amend maintainers or other package metadata, or perform any other action the user is authorised to do.
A critical stored cross-site scripting vulnerability has been identified in Hackage-Server, affecting version 0.5 and prior. This vulnerability arises because HTML and JavaScript files uploaded as source packages or through the documentation upload feature are served without sanitization on the main Hackage Haskell domain. As a result, when a user with active HTTP credentials visits package pages or documentation from a malicious maintainer, their session can be hijacked. This allows the attacker to upload packages or documentation, modify maintainer details or other package metadata, or execute any other actions the user is authorized to perform.
Users of Hackage-Server should update to version 0.6 or later and configure the user content domain to `hackage-content.haskell.org`. Instructions for updating can be found in the Hackage-Server GitHub repository.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 23, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://osv.dev/vulnerability/HSEC-2024-0004 | redhat-cnalr |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | redhat-cnalr |
Affected Products
No affected product data is available for this CVE.
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | redhat-cnalr |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 23, 2026 | New CVE Received | redhat-cnalr |