CVE-2026-40470

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
23/04/2026
Last modified:
24/04/2026

Description

A critical XSS vulnerability affected hackage-server and<br /> hackage.haskell.org. HTML and JavaScript files provided in source<br /> packages or via the documentation upload facility were served<br /> as-is on the main hackage.haskell.org domain. As a consequence,<br /> when a user with latent HTTP credentials browses to the package<br /> pages or documentation uploaded by a malicious package maintainer,<br /> their session can be hijacked to upload packages or<br /> documentation, amend maintainers or other package metadata, or<br /> perform any other action the user is authorised to do.

References to Advisories, Solutions, and Tools