Description
Inappropriate Encoding for Output Context vulnerability in joshnuss xml_builder (XmlBuilder module) allows Content Spoofing, Cross-site Scripting.

This vulnerability is associated with program files lib/xml_builder.ex and program routines XmlBuilder.generate/1, XmlBuilder.generate/2, XmlBuilder.escape_string/1, XmlBuilder.escape_entity/1.

XmlBuilder.generate/1 does not escape literal & characters in text or attribute values when they are followed by an entity-like token (lt;, gt;, amp;, quot;, apos;). As a result, attacker-supplied input such as &lt;script&gt; is emitted verbatim into the serialized XML rather than being escaped to &amp;lt;script&amp;gt;. When a downstream XML parser later reads the document, it decodes the entity sequences into the literal characters <script>, promoting inert-looking text into real markup. This allows an attacker to bypass upstream filters that block raw < and > characters, injecting markup into any downstream consumer that parses the produced XML and renders the text content in a markup-sensitive context (HTML, SVG, RSS/Atom feeds). Both element text and attribute values are affected.

This issue affects xml_builder: from 0.0.6 before 2.4.1.
Published: 2026-08-21
Score: 2.1 Low
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The defect is in the xml_builder library’s generate and escape routines. When a literal & is followed by an entity- like token, the library does not escape the & and emits the sequence directly into the XML output. A downstream XML parser then resolves the sequence into the intended characters, turning inert-looking text such as &lt;script&gt; into executable markup. This flaw enables attackers to spoof content and inject cross‑site scripting payloads into any downstream consumer that parses the produced XML and renders it in a markup‑sensitive context, such as HTML, SVG, or RSS feeds. The weakness is classified as CWE-838, Improper Output Encoding.

Affected Systems

The strconv library joshnuss xml_builder is affected for all releases from version 0.0.6 up to, but not including, 2.4.1. Users of any preceding or later versions are not vulnerable.

Risk and Exploitability

The CVSS score is 2.1, indicating low severity and the EPSS metric is not available, while the vulnerability is not listed in the CISA KEV catalog. Attackers need only supply malicious input to the xml_builder functions, which may occur when user data is emitted as XML. Although the flaw does not grant remote code execution, the potential for XSS and content spoofing can compromise client‑side security and lead to further attacks. The attack path is typically local to the application, but any external party that can influence the XML content could exploit it.

Generated by OpenCVE AI on August 21, 2026 at 11:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade joshnuss xml_builder to version 2.4.1 or newer, which removes the improper escaping logic.
  • If an upgrade is not feasible, patch the escape_string or escape_entity functions so that every & preceding an entity‑like token is correctly encoded as &amp;.
  • Calibrate the input feeding xml_builder to strip or encode entity sequences before invocation, ensuring downstream parsers receive safe XML.

Generated by OpenCVE AI on August 21, 2026 at 11:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 10:00:00 +0000

Type Values Removed Values Added
Description Inappropriate Encoding for Output Context vulnerability in joshnuss xml_builder (XmlBuilder module) allows Content Spoofing, Cross-site Scripting. This vulnerability is associated with program files lib/xml_builder.ex and program routines XmlBuilder.generate/1, XmlBuilder.generate/2, XmlBuilder.escape_string/1, XmlBuilder.escape_entity/1. XmlBuilder.generate/1 does not escape literal & characters in text or attribute values when they are followed by an entity-like token (lt;, gt;, amp;, quot;, apos;). As a result, attacker-supplied input such as &lt;script&gt; is emitted verbatim into the serialized XML rather than being escaped to &amp;lt;script&amp;gt;. When a downstream XML parser later reads the document, it decodes the entity sequences into the literal characters <script>, promoting inert-looking text into real markup. This allows an attacker to bypass upstream filters that block raw < and > characters, injecting markup into any downstream consumer that parses the produced XML and renders the text content in a markup-sensitive context (HTML, SVG, RSS/Atom feeds). Both element text and attribute values are affected. This issue affects xml_builder: from 0.0.6 before 2.4.1.
Title Round-trip Corruption via Improper Entity Escaping in xml_builder
First Time appeared Joshnuss
Joshnuss xml Builder
Weaknesses CWE-838
CPEs cpe:2.3:a:joshnuss:xml_builder:*:*:*:*:*:*:*:*
Vendors & Products Joshnuss
Joshnuss xml Builder
References
Metrics cvssV4_0

{'score': 2.1, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N'}


Subscriptions

Joshnuss Xml Builder
cve-icon MITRE

Status: PUBLISHED

Assigner: EEF

Published:

Updated: 2026-08-21T12:19:47.179Z

Reserved: 2026-05-18T17:28:10.319Z

Link: CVE-2026-47079

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-21T10:16:38.167

Modified: 2026-08-21T10:16:38.167

Link: CVE-2026-47079

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T11:30:04Z

Weaknesses
  • CWE-838

    Inappropriate Encoding for Output Context