[Bug 298818] www/adjuster: Update to v3.25, and annogen v3.43 with security fix
- Reply: bugzilla-noreply_a_freebsd.org: "[Bug 298818] www/adjuster: Update to v3.25, and annogen v3.43 with security fix"
- Reply: bugzilla-noreply_a_freebsd.org: "[Bug 298818] www/adjuster: Update to v3.25, and annogen v3.43 with security fix"
- Reply: bugzilla-noreply_a_freebsd.org: "[Bug 298818] www/adjuster: Update to v3.25, and annogen v3.43 with security fix"
- Reply: bugzilla-noreply_a_freebsd.org: "[Bug 298818] www/adjuster: Update to v3.25, and annogen v3.43 with security fix"
- Reply: bugzilla-noreply_a_freebsd.org: "[Bug 298818] www/adjuster: Update to v3.25, and annogen v3.43 with security fix"
- Reply: bugzilla-noreply_a_freebsd.org: "[Bug 298818] www/adjuster: Update to v3.25, and annogen v3.43 with security fix"
- Reply: bugzilla-noreply_a_freebsd.org: "[Bug 298818] www/adjuster: Update to v3.25, and annogen v3.43 with security fix"
- Reply: bugzilla-noreply_a_freebsd.org: "[Bug 298818] www/adjuster: Update to v3.25, and annogen v3.43 with security fix"
- Reply: bugzilla-noreply_a_freebsd.org: "[Bug 298818] www/adjuster: Update to v3.25, and annogen v3.43 with security fix"
- Reply: bugzilla-noreply_a_freebsd.org: "[Bug 298818] www/adjuster: Update to v3.25, and annogen v3.43 with security fix"
- Go to: [ bottom of page ] [ top of archives ] [ this month ]
Date: Thu, 24 Sep 2026 13:07:32 UTC
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=298818
Bug ID: 298818
Summary: www/adjuster: Update to v3.25, and annogen v3.43 with
security fix
Product: Ports & Packages
Version: Latest
Hardware: Any
OS: Any
Status: New
Severity: Affects Only Me
Priority: ---
Component: Individual Port(s)
Assignee: ports-bugs@FreeBSD.org
Reporter: ssb22@cam.ac.uk
Created attachment 275071
--> https://bugs.freebsd.org/bugzilla/attachment.cgi?id=275071&action=edit
Patch for updating to v3.25
This patch updates Web Adjuster to version 3.25, adding a native cgi option (no
need for WSGI) and fixing Python 3 compatibility for non-function htmlFilter
settings.
More importantly, it also updates Annotator Generator to version 3.43 which
fixes a cross-site scripting vulnerability.
The vulnerability was reported by Shubham Agarwal of the Max Planck Institute
for Security and Privacy and Saarland University, via the Chaos study ("How
Websites May Disrupt Browser Extensions"), against the Pinyin Web Chrome
extension, the core code of which is from Annotator Generator.
In affected versions, text-node content that had been de-escaped by the DOM was
copied into HTML output without re-escaping, allowing a malicious post mixing
Chinese text with escaped <img onerror=...> markup to execute JavaScript. This
could have allowed cookie-stealing on social-media sites that normally rely on
escaping of HTML to prevent untrusted scripts in their posts.
The Annotator Generator fix escapes & and < in input text on HTML output paths
across all five generated language targets (C, Java, JavaScript, Dart and
Python).
--
You are receiving this mail because:
You are the assignee for the bug.