This vulnerability is associated with program files lib/xml_builder.ex and program routines XmlBuilder.generate/1, XmlBuilder.generate/2, XmlBuilder.escape/1.
The escape/1 clause for {:cdata, data} in lib/xml_builder.ex concatenates data verbatim between the CDATA opener <![CDATA[ and closer ]]> without rewriting or splitting on the embedded ]]> sequence. Because CDATA sections have no internal escape mechanism, the only safe way to embed arbitrary bytes is to split on ]]> and emit adjacent CDATA sections. An attacker who can supply input containing ]]> closes the CDATA section early; any bytes that follow are parsed as ordinary XML markup by downstream consumers, allowing injection of arbitrary elements, text, or entity references into the output document.
This issue affects xml_builder: from 0.0.7 before 2.4.1.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 21 Aug 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
ssvc
|
Fri, 21 Aug 2026 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | XML Injection vulnerability in joshnuss xml_builder (XmlBuilder module) allows Content Spoofing, XML Injection. This vulnerability is associated with program files lib/xml_builder.ex and program routines XmlBuilder.generate/1, XmlBuilder.generate/2, XmlBuilder.escape/1. The escape/1 clause for {:cdata, data} in lib/xml_builder.ex concatenates data verbatim between the CDATA opener <![CDATA[ and closer ]]> without rewriting or splitting on the embedded ]]> sequence. Because CDATA sections have no internal escape mechanism, the only safe way to embed arbitrary bytes is to split on ]]> and emit adjacent CDATA sections. An attacker who can supply input containing ]]> closes the CDATA section early; any bytes that follow are parsed as ordinary XML markup by downstream consumers, allowing injection of arbitrary elements, text, or entity references into the output document. This issue affects xml_builder: from 0.0.7 before 2.4.1. | |
| Title | CDATA Section Breakout via Unsanitised ]]> in xml_builder | |
| First Time appeared |
Joshnuss
Joshnuss xml Builder |
|
| Weaknesses | CWE-91 | |
| CPEs | cpe:2.3:a:joshnuss:xml_builder:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Joshnuss
Joshnuss xml Builder |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: EEF
Published:
Updated: 2026-08-21T12:32:15.846Z
Reserved: 2026-05-18T17:28:10.319Z
Link: CVE-2026-47080
Updated: 2026-08-21T12:30:21.762Z
Status : Received
Published: 2026-08-21T10:16:38.497
Modified: 2026-08-21T13:18:06.050
Link: CVE-2026-47080
No data.
OpenCVE Enrichment
Updated: 2026-08-21T14:00:13Z