Description
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in the HTML5 scrubber in rrrene html_sanitize_ex allows a remote attacker to force visitors of a page to navigate to a site of the attacker's choosing via a <meta http-equiv="refresh"> element in sanitized HTML. HtmlSanitizeEx.html5/1 keeps attacker-supplied <meta> elements in its output. A meta element acts on the whole document rather than on the fragment it was embedded in, so it can also declare document-wide directives such as Content-Security-Policy.

This is not cross-site scripting. Browsers do not navigate a meta refresh to a javascript: URL, so the uppercase JAVASCRIPT: filter bypass yields no script execution and none was demonstrated.

This issue affects html_sanitize_ex: from 0.3.1 before 1.5.3.
Published: 2026-08-06
Score: 2.3 Low
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A meta element supplied by an attacker and passed through the HTML5 scrubber in html_sanitize_ex remains in the sanitized output, enabling an attacker to force a user’s browser to navigate to an untrusted site via a <meta http-equiv="refresh"> tag. Because the meta directive applies to the entire document rather than just the fragment, it can also declare global directives such as Content‑Security‑Policy, potentially weakening security constraints for the visitor. The vulnerability does not allow script execution; browsers do not process a meta refresh targeting a javascript: URL, so the weakness is limited to open redirect and policy manipulation. This is categorized as CWE‑601, an Open Redirect flaw.

Affected Systems

The vulnerability affects the rrrene html_sanitize_ex library, specifically versions from 0.3.1 up through but excluding 1.5.3. Systems that incorporate this library to sanitize user‑supplied HTML for display in a browser are at risk if the HTML sanitizer is used without filtering out meta tags.

Risk and Exploitability

The CVSS score of 2.3 indicates low severity, and no exploit probability score is available. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a server that accepts untrusted HTML input, passes it through html_sanitize_ex, and renders the sanitized output in a browser. An attacker can embed a meta refresh tag in the input to coerce any user who views the page to be redirected to an arbitrary site. While the risk of exploitation is considered low, it still permits a user‑targeted redirection that can be socially engineered for phishing or traffic manipulation.

Generated by OpenCVE AI on August 6, 2026 at 16:43 UTC.

Remediation

Vendor Workaround

Sanitize with basic_html/1, markdown_html/1 or strip_tags/1, none of which allow meta, or define a custom scrubber that omits it.


OpenCVE Recommended Actions

  • Upgrade html_sanitize_ex to version 1.5.3 or later, which eliminates the meta element from sanitized output.
  • If an upgrade is not immediately possible, use the basic_html/1, markdown_html/1, or strip_tags/1 functions, all of which do not allow meta tags.
  • Define and apply a custom scrubber that explicitly removes meta elements before rendering.
  • Ensure that processed HTML is not subsequently re‑parsed or re‑sanitized in a context that reinserts meta tags.

Generated by OpenCVE AI on August 6, 2026 at 16:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 06 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Description URL Redirection to Untrusted Site ('Open Redirect') vulnerability in the HTML5 scrubber in rrrene html_sanitize_ex allows a remote attacker to force visitors of a page to navigate to a site of the attacker's choosing via a <meta http-equiv="refresh"> element in sanitized HTML. HtmlSanitizeEx.html5/1 keeps attacker-supplied <meta> elements in its output. A meta element acts on the whole document rather than on the fragment it was embedded in, so it can also declare document-wide directives such as Content-Security-Policy. This is not cross-site scripting. Browsers do not navigate a meta refresh to a javascript: URL, so the uppercase JAVASCRIPT: filter bypass yields no script execution and none was demonstrated. This issue affects html_sanitize_ex: from 0.3.1 before 1.5.3.
Title html_sanitize_ex HTML5 scrubber keeps attacker-supplied meta refresh, allowing forced cross-origin redirection
First Time appeared Rrrene
Rrrene html Sanitize Ex
Weaknesses CWE-601
CPEs cpe:2.3:a:rrrene:html_sanitize_ex:*:*:*:*:*:*:*:*
Vendors & Products Rrrene
Rrrene html Sanitize Ex
References
Metrics cvssV4_0

{'score': 2.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N'}


Subscriptions

Rrrene Html Sanitize Ex
cve-icon MITRE

Status: PUBLISHED

Assigner: EEF

Published:

Updated: 2026-08-06T14:49:23.468Z

Reserved: 2026-08-06T08:15:02.719Z

Link: CVE-2026-66829

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-06T16:45:07Z

Weaknesses
  • CWE-601

    URL Redirection to Untrusted Site ('Open Redirect')