Description
HTML::FormHandler versions before 0.410002 for Perl render option group labels and radio button labels into HTML without escaping.

The Select, RadioGroup, CheckboxGroup and HorizCheckboxGroup widgets render a group label unescaped, Select into a label attribute and the other three into element content. RadioGroup also renders each radio button's own label unescaped.

Any application whose option list is built from data rather than literals, using options_from, an options_fieldname method, or the DBIC model, allows attacker-influenced text in a label that can override the options or embed JavaScript in rendered pages.
Published: 2026-09-08
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Cross‑Site Scripting
Action: Immediate Patch
AI Analysis

Impact

HTML::FormHandler versions before 0.410002 generate option group labels and radio button labels directly into the HTML output without escaping. The unescaped labels can contain arbitrary markup or JavaScript code. If an attacker can influence the text that populates these labels—through options_from, options_fieldname, or a DBIC model—the resulting page can execute script code in a user’s browser, altering the form’s appearance or behavior. The vulnerability directly permits the injection of script that may affect any user who visits the page. Based on the description, it is inferred that the attacker must be able to supply the option labels.

Affected Systems

Any Perl application that incorporates the HTML::FormHandler module in a version earlier than 0.410002 is potentially vulnerable. The issue is present in the Select, RadioGroup, CheckboxGroup render the group labels or option labels unescaped. This includes all CPAN releases and derivative packages that have not applied the publisher’s patch or updated to the fixed version. Applications that dynamically generate option lists from user‑supplied data or database models are also affected.

Risk and Exploitability

Based on the description, the likely attack vector is that an attacker can influence the content of a form’s option list via options_from, options_fieldname, or a DBIC model. The security analysis indicates a moderate‑impact XSS flaw, with a CVSS score of 6.1. The EPSS score is less than 1%, and the vulnerability is not listed in CISA KEV, suggesting limited observed exploitation. The attack vector requires an attacker to control the content of a form’s option list; if such control is possible—e.g., via an API, form input, or database model—the attacker can supply malicious labels that are rendered unescaped. This leads to direct script execution in a visitor’s browser, potentially compromising the user experience and data integrity.

Generated by OpenCVE AI on September 10, 2026 at 23:35 UTC.

Remediation

Vendor Solution

Upgrade to HTML-FormHandler 0.410002 or later.


OpenCVE Recommended Actions

  • Upgrade HTML::FormHandler to version 0.410002 or later.
  • If an update cannot be applied immediately, sanitise any text passed to options_from, options_fieldname, or DBIC models before it is supplied to the form widgets, ensuring characters are properly encoded.
  • Limit dynamic option list generation to trusted, validated sources or perform strict input validation to prevent untrusted content from reaching the renderer.
  • Review custom or third‑party form widgets that rely on the affected components and apply their own output encoding or replace them with secure alternatives.

Generated by OpenCVE AI on September 10, 2026 at 23:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
First Time appeared Gshank
Gshank html::formhandler
Vendors & Products Gshank
Gshank html::formhandler

Thu, 10 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 23:30:00 +0000

Type Values Removed Values Added
References

Tue, 08 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description HTML::FormHandler versions before 0.410002 for Perl render option group labels and radio button labels into HTML without escaping. The Select, RadioGroup, CheckboxGroup and HorizCheckboxGroup widgets render a group label unescaped, Select into a label attribute and the other three into element content. RadioGroup also renders each radio button's own label unescaped. Any application whose option list is built from data rather than literals, using options_from, an options_fieldname method, or the DBIC model, allows attacker-influenced text in a label that can override the options or embed JavaScript in rendered pages.
Title HTML::FormHandler versions before 0.410002 for Perl render option group labels and radio button labels into HTML without escaping
Weaknesses CWE-79
References

Subscriptions

Gshank Html::formhandler
cve-icon MITRE

Status: PUBLISHED

Assigner: CPANSec

Published:

Updated: 2026-09-10T17:50:45.828Z

Reserved: 2026-09-03T21:29:54.878Z

Link: CVE-2026-85484

cve-icon Vulnrichment

Updated: 2026-09-08T22:07:19.249Z

cve-icon NVD

Status : Deferred

Published: 2026-09-08T20:18:51.453

Modified: 2026-09-10T18:18:09.550

Link: CVE-2026-85484

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T06:00:09Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')