CVE-2026-40470
Severity CVSS v4.0:
Pending analysis
Type:
CWE-79
Cross-Site Scripting (XSS)
Publication date:
23/04/2026
Last modified:
24/04/2026
Description
A critical XSS vulnerability affected hackage-server and<br />
hackage.haskell.org. HTML and JavaScript files provided in source<br />
packages or via the documentation upload facility were served<br />
as-is on the main hackage.haskell.org domain. As a consequence,<br />
when a user with latent HTTP credentials browses to the package<br />
pages or documentation uploaded by a malicious package maintainer,<br />
their session can be hijacked to upload packages or<br />
documentation, amend maintainers or other package metadata, or<br />
perform any other action the user is authorised to do.
Impact
Base Score 3.x
9.90
Severity 3.x
CRITICAL



