This vulnerability is associated with program files lib/xml_builder.ex and program routines XmlBuilder.generate/1, XmlBuilder.generate/2, XmlBuilder.element/1, XmlBuilder.element/2, XmlBuilder.element/3.
Element names, attribute names, and doctype identifiers are interpolated verbatim into the serialized XML output without validation or escaping of structural characters (<, >, ", ', &). An attacker who can influence a name argument (for example, an element name derived from a JSON object key or an HTTP form field name) can inject arbitrary XML markup including extra elements, comments, and event-handler attributes into the output document.
This issue affects xml_builder: from 0.0.1 before 2.4.1.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 21 Aug 2026 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | XML Injection vulnerability in joshnuss xml_builder (XmlBuilder module) allows Content Spoofing, XML Injection. This vulnerability is associated with program files lib/xml_builder.ex and program routines XmlBuilder.generate/1, XmlBuilder.generate/2, XmlBuilder.element/1, XmlBuilder.element/2, XmlBuilder.element/3. Element names, attribute names, and doctype identifiers are interpolated verbatim into the serialized XML output without validation or escaping of structural characters (<, >, ", ', &). An attacker who can influence a name argument (for example, an element name derived from a JSON object key or an HTTP form field name) can inject arbitrary XML markup including extra elements, comments, and event-handler attributes into the output document. This issue affects xml_builder: from 0.0.1 before 2.4.1. | |
| Title | Element and Attribute Names Injected Verbatim into XML Output in xml_builder | |
| First Time appeared |
Joshnuss
Joshnuss xml Builder |
|
| Weaknesses | CWE-91 | |
| CPEs | cpe:2.3:a:joshnuss:xml_builder:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Joshnuss
Joshnuss xml Builder |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: EEF
Published:
Updated: 2026-08-21T09:51:25.412Z
Reserved: 2026-05-22T09:36:56.833Z
Link: CVE-2026-48590
No data.
Status : Received
Published: 2026-08-21T10:16:38.767
Modified: 2026-08-21T10:16:38.767
Link: CVE-2026-48590
No data.
OpenCVE Enrichment
No data.