Description
HTML::FormHandler versions before 0.410002 for Perl render field attributes into HTML without escaping using the process_attrs method.

Any application with fields or field labels where some attributes are built from data rather than literals allows attacker-influenced text in an attribute value that can override the field attributes or embed JavaScript in rendered pages.

For example, the RadioGroup widget uses the process_attrs method via the render_option and wrap_radio methods.
Published: 2026-09-08
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Cross‑Site Scripting via Unescaped HTML Attributes
Action: Patch Immediately
AI Analysis

Impact

HTML::FormHandler versions prior to 0.410002 render field attributes into HTML using the process_attrs method without escaping. Any attribute value that is constructed from user input or variable data, rather than hard‑coded literals, can inject arbitrary text into an attribute value. This flaw enables an attacker to override default field attributes or insert JavaScript code into rendered pages, giving the attacker the ability to execute script in the victim’s browser context.

Affected Systems

The vulnerability exists in the Perl module HTML::FormHandler before version 0.410002. Applications that employ this module to generate form elements—particularly widgets such as RadioGroup that invoke process_attrs through render_option and wrap_radio—are affected. No vendor or product version list is provided beyond the module’s internal version numbering.

Risk and Exploitability

The CVSS score of 6.1 indicates a moderate severity for this reflected XSS flaw. Based on the description, it is inferred that the vulnerability is triggered when an attacker can influence attribute values, and because it is a server‑side rendering issue, the attacker does not need to compromise the server; a crafted request that includes malicious attribute data could trigger the flaw. The EPSS score of < 1% indicates a low probability of exploitation, and the vulnerability is not listed in the CISA KE no known public exploits. However, the lack of escaping means that the risk remains significant for exposed web applications that rely on dynamic attribute construction.

Generated by OpenCVE AI on September 11, 2026 at 00:02 UTC.

Remediation

Vendor Solution

Upgrade to HTML-FormHandler 0.410002 or later.


OpenCVE Recommended Actions

  • Apply the HTML::FormHandler 0.410002 or later patch to ensure attribute values are escaped before rendering.
  • Sanitize or encode any user‑supplied data that is passed to process_attrs, and verify that all attribute values are strictly validated against a whitelist of allowed characters.
  • If upgrading is not immediately possible, disable or replace widgets that create dynamic attributes—such as RadioGroup—until a patched version can be deployed.

Generated by OpenCVE AI on September 11, 2026 at 00:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 13 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Gshank
Gshank html::formhandler
Vendors & Products Gshank
Gshank html::formhandler

Thu, 10 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 23:30:00 +0000

Type Values Removed Values Added
References

Tue, 08 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description HTML::FormHandler versions before 0.410002 for Perl render field attributes into HTML without escaping using the process_attrs method. Any application with fields or field labels where some attributes are built from data rather than literals allows attacker-influenced text in an attribute value that can override the field attributes or embed JavaScript in rendered pages. For example, the RadioGroup widget uses the process_attrs method via the render_option and wrap_radio methods.
Title HTML::FormHandler versions before 0.410002 for Perl render field attributes into HTML without escaping using the process_attrs method
Weaknesses CWE-79
References

Subscriptions

Gshank Html::formhandler
cve-icon MITRE

Status: PUBLISHED

Assigner: CPANSec

Published:

Updated: 2026-09-10T17:48:34.720Z

Reserved: 2026-09-04T11:33:35.572Z

Link: CVE-2026-85630

cve-icon Vulnrichment

Updated: 2026-09-08T22:07:20.485Z

cve-icon NVD

Status : Deferred

Published: 2026-09-08T20:18:51.663

Modified: 2026-09-10T18:18:09.860

Link: CVE-2026-85630

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-13T20:07:10Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')