Inappropriate Encoding in xml_builder 0.0.62.4.1: XSS via <script
CVE-2026-47079 Published on August 21, 2026
Round-trip Corruption via Improper Entity Escaping in xml_builder
Inappropriate Encoding for Output Context vulnerability in joshnuss xml_builder (XmlBuilder module) allows Content Spoofing, Cross-site Scripting.
This vulnerability is associated with program files lib/xml_builder.ex and program routines XmlBuilder.generate/1, XmlBuilder.generate/2, XmlBuilder.escape_string/1, XmlBuilder.escape_entity/1.
XmlBuilder.generate/1 does not escape literal & characters in text or attribute values when they are followed by an entity-like token (lt;, gt;, amp;, quot;, apos;). As a result, attacker-supplied input such as <script> is emitted verbatim into the serialized XML rather than being escaped to &lt;script&gt;. When a downstream XML parser later reads the document, it decodes the entity sequences into the literal characters <script>, promoting inert-looking text into real markup. This allows an attacker to bypass upstream filters that block raw < and > characters, injecting markup into any downstream consumer that parses the produced XML and renders the text content in a markup-sensitive context (HTML, SVG, RSS/Atom feeds). Both element text and attribute values are affected.
This issue affects xml_builder: from 0.0.6 before 2.4.1.
Vulnerability Analysis
CVE-2026-47079 can be exploited with local system access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality and integrity and availability.
Weakness Type
Inappropriate Encoding for Output Context
The software uses or specifies an encoding when generating output to a downstream component, but the specified encoding is not the same as the encoding that is expected by the downstream component.
Products Associated with CVE-2026-47079
Want to know whenever a new CVE is published for Joshnuss Xml Builder? stack.watch will email you.
Affected Versions
joshnuss xml_builder:- Version 0.0.6 and below 2.4.1 is affected.
- Version aae31e6e8ac837bcbb8afb816c0d14324b5cfe2b and below c3390e2046ec297b3bb8c30d5779cdfd6508c275 is affected.