CVE-2026-40470

Published Apr 23, 2026

Last updated 6 hours ago

Overview

Description
A critical XSS vulnerability affected hackage-server and hackage.haskell.org. HTML and JavaScript files provided in source packages or via the documentation upload facility were served as-is on the main hackage.haskell.org domain. As a consequence, when a user with latent HTTP credentials browses to the package pages or documentation uploaded by a malicious package maintainer, their session can be hijacked to upload packages or documentation, amend maintainers or other package metadata, or perform any other action the user is authorised to do.
Source
74b3a70d-cca6-4d34-9789-e83b222ae3be
NVD status
Received

Risk scores

CVSS 3.1

Type
Secondary
Base score
9.9
Impact score
6
Exploitability score
3.1
Vector string
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L
Severity
CRITICAL

Weaknesses

74b3a70d-cca6-4d34-9789-e83b222ae3be
CWE-79

Social media

Hype score
Not currently trending

References

Sources include official advisories and independent security research.