This vulnerability is associated with program files lib/xml_builder.ex and program routines XmlBuilder.generate/1, XmlBuilder.generate/2, XmlBuilder.element/1, XmlBuilder.element/2, XmlBuilder.element/3.
Element names, attribute names, and doctype identifiers are interpolated verbatim into the serialized XML output without validation or escaping of structural characters (<, >, ", ', &). An attacker who can influence a name argument (for example, an element name derived from a JSON object key or an HTTP form field name) can inject arbitrary XML markup including extra elements, comments, and event-handler attributes into the output document.
This issue affects xml_builder: from 0.0.1 before 2.4.1.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 21 Aug 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 21 Aug 2026 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | XML Injection vulnerability in joshnuss xml_builder (XmlBuilder module) allows Content Spoofing, XML Injection. This vulnerability is associated with program files lib/xml_builder.ex and program routines XmlBuilder.generate/1, XmlBuilder.generate/2, XmlBuilder.element/1, XmlBuilder.element/2, XmlBuilder.element/3. Element names, attribute names, and doctype identifiers are interpolated verbatim into the serialized XML output without validation or escaping of structural characters (<, >, ", ', &). An attacker who can influence a name argument (for example, an element name derived from a JSON object key or an HTTP form field name) can inject arbitrary XML markup including extra elements, comments, and event-handler attributes into the output document. This issue affects xml_builder: from 0.0.1 before 2.4.1. | |
| Title | Element and Attribute Names Injected Verbatim into XML Output in xml_builder | |
| First Time appeared |
Joshnuss
Joshnuss xml Builder |
|
| Weaknesses | CWE-91 | |
| CPEs | cpe:2.3:a:joshnuss:xml_builder:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Joshnuss
Joshnuss xml Builder |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: EEF
Published:
Updated: 2026-08-21T12:25:33.127Z
Reserved: 2026-05-22T09:36:56.833Z
Link: CVE-2026-48590
Updated: 2026-08-21T12:25:23.775Z
Status : Received
Published: 2026-08-21T10:16:38.767
Modified: 2026-08-21T13:18:06.993
Link: CVE-2026-48590
No data.
OpenCVE Enrichment
Updated: 2026-08-21T12:07:56Z
-
CWE-91
XML Injection (aka Blind XPath Injection)