Description
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in the HTML5 scrubber in rrrene html_sanitize_ex allows a remote attacker to force visitors of a page to navigate to a site of the attacker's choosing via a <meta http-equiv="refresh"> element in sanitized HTML. HtmlSanitizeEx.html5/1 keeps attacker-supplied <meta> elements in its output. A meta element acts on the whole document rather than on the fragment it was embedded in, so it can also declare document-wide directives such as Content-Security-Policy.

This is not cross-site scripting. Browsers do not navigate a meta refresh to a javascript: URL, so the uppercase JAVASCRIPT: filter bypass yields no script execution and none was demonstrated.

This issue affects html_sanitize_ex: from 0.3.1 before 1.4.5 and from 1.5.0-rc.0 before 1.5.3.
Published: 2026-08-06
Score: 2.3 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The CVE describes an open redirect vulnerability in the HTML5 scrubber component of the rrrene html_sanitize_ex library. Attackers can embed a <meta http-equiv="refresh"> element that the HtmlSanitizeEx.html5/1 sanitizer preserves, enabling browsers to redirect users to any site specified by the attacker. The meta tag applies to the entire document rather than just the embedded fragment, allowing it to declare document-wide directives such as Content‑Security‑Policy. Unlike XSS, the library does not execute JavaScript in meta refresh tags, so no script execution is possible. The issue affects html_sanitize_ex versions from 0.3.1 through before 1.4.5 and from 1.5.0‑rc.0 through before 1.5.3, and is classified under CWE‑601.

Affected Systems

The vulnerability affects the rrrene html_sanitize_ex library, specifically versions from 0.3.1 up through but excluding 1.5.3. Systems that incorporate this library to sanitize user‑supplied HTML for display in a browser are at risk if the HTML sanitizer is used without filtering out meta tags.

Risk and Exploitability

The CVSS score of 2.3 indicates low severity, and the EPSS score is below 1%, implying a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a server that accepts untrusted HTML input, passes it through html_sanitize_ex, and renders the sanitized output in a browser. An attacker can embed a meta refresh tag in the input to coerce any user who views the page to be redirected to an arbitrary site. While the risk of exploitation is considered low, it still permits a user‑targeted redirection that can be socially engineered for phishing or traffic manipulation.

Generated by OpenCVE AI on August 22, 2026 at 10:26 UTC.

Remediation

Vendor Workaround

Sanitize with basic_html/1, markdown_html/1 or strip_tags/1, none of which allow meta, or define a custom scrubber that omits it.


OpenCVE Recommended Actions

  • Upgrade html_sanitize_ex to version 1.5.3 or later, which eliminates the meta element from sanitized output.
  • If an upgrade is not immediately possible, use the basic_html/1, markdown_html/1, or strip_tags/1 functions, all of which do not allow meta tags.
  • Define and apply a custom scrubber that explicitly removes meta elements before rendering.
  • Ensure that processed HTML is not subsequently re‑parsed or re‑sanitized in a context that reinserts meta tags.

Generated by OpenCVE AI on August 22, 2026 at 10:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 19 Aug 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 12:00:00 +0000

Type Values Removed Values Added
Description URL Redirection to Untrusted Site ('Open Redirect') vulnerability in the HTML5 scrubber in rrrene html_sanitize_ex allows a remote attacker to force visitors of a page to navigate to a site of the attacker's choosing via a <meta http-equiv="refresh"> element in sanitized HTML. HtmlSanitizeEx.html5/1 keeps attacker-supplied <meta> elements in its output. A meta element acts on the whole document rather than on the fragment it was embedded in, so it can also declare document-wide directives such as Content-Security-Policy. This is not cross-site scripting. Browsers do not navigate a meta refresh to a javascript: URL, so the uppercase JAVASCRIPT: filter bypass yields no script execution and none was demonstrated. This issue affects html_sanitize_ex: from 0.3.1 before 1.5.3. URL Redirection to Untrusted Site ('Open Redirect') vulnerability in the HTML5 scrubber in rrrene html_sanitize_ex allows a remote attacker to force visitors of a page to navigate to a site of the attacker's choosing via a <meta http-equiv="refresh"> element in sanitized HTML. HtmlSanitizeEx.html5/1 keeps attacker-supplied <meta> elements in its output. A meta element acts on the whole document rather than on the fragment it was embedded in, so it can also declare document-wide directives such as Content-Security-Policy. This is not cross-site scripting. Browsers do not navigate a meta refresh to a javascript: URL, so the uppercase JAVASCRIPT: filter bypass yields no script execution and none was demonstrated. This issue affects html_sanitize_ex: from 0.3.1 before 1.4.5 and from 1.5.0-rc.0 before 1.5.3.
References

Tue, 11 Aug 2026 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Rrrene htmlsanitizeex
CPEs cpe:2.3:a:rrrene:htmlsanitizeex:*:*:*:*:*:*:*:*
Vendors & Products Rrrene htmlsanitizeex
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


Thu, 06 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Description URL Redirection to Untrusted Site ('Open Redirect') vulnerability in the HTML5 scrubber in rrrene html_sanitize_ex allows a remote attacker to force visitors of a page to navigate to a site of the attacker's choosing via a <meta http-equiv="refresh"> element in sanitized HTML. HtmlSanitizeEx.html5/1 keeps attacker-supplied <meta> elements in its output. A meta element acts on the whole document rather than on the fragment it was embedded in, so it can also declare document-wide directives such as Content-Security-Policy. This is not cross-site scripting. Browsers do not navigate a meta refresh to a javascript: URL, so the uppercase JAVASCRIPT: filter bypass yields no script execution and none was demonstrated. This issue affects html_sanitize_ex: from 0.3.1 before 1.5.3.
Title html_sanitize_ex HTML5 scrubber keeps attacker-supplied meta refresh, allowing forced cross-origin redirection
First Time appeared Rrrene
Rrrene html Sanitize Ex
Weaknesses CWE-601
CPEs cpe:2.3:a:rrrene:html_sanitize_ex:*:*:*:*:*:*:*:*
Vendors & Products Rrrene
Rrrene html Sanitize Ex
References
Metrics cvssV4_0

{'score': 2.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N'}


Subscriptions

Rrrene Html Sanitize Ex Htmlsanitizeex
cve-icon MITRE

Status: PUBLISHED

Assigner: EEF

Published:

Updated: 2026-08-19T11:50:39.885Z

Reserved: 2026-08-06T08:15:02.719Z

Link: CVE-2026-66829

cve-icon Vulnrichment

Updated: 2026-08-06T15:42:42.992Z

cve-icon NVD

Status : Modified

Published: 2026-08-06T16:16:49.450

Modified: 2026-08-19T12:18:34.627

Link: CVE-2026-66829

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-22T10:30:17Z

Weaknesses
  • CWE-601

    URL Redirection to Untrusted Site ('Open Redirect')