CVE-2026-47079
Received Received - Intake

Inappropriate Encoding for Output Context in xml_builder Allows XSS

Vulnerability report for CVE-2026-47079, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-21

Last updated on: 2026-08-21

Assigner: EEF

Description

Inappropriate Encoding for Output Context vulnerability in joshnuss xml_builder (XmlBuilder module) allows Content Spoofing, Cross-site Scripting. This vulnerability is associated with program files lib/xml_builder.ex and program routines XmlBuilder.generate/1, XmlBuilder.generate/2, XmlBuilder.escape_string/1, XmlBuilder.escape_entity/1. XmlBuilder.generate/1 does not escape literal & characters in text or attribute values when they are followed by an entity-like token (lt;, gt;, amp;, quot;, apos;). As a result, attacker-supplied input such as &lt;script&gt; is emitted verbatim into the serialized XML rather than being escaped to &amp;lt;script&amp;gt;. When a downstream XML parser later reads the document, it decodes the entity sequences into the literal characters <script>, promoting inert-looking text into real markup. This allows an attacker to bypass upstream filters that block raw < and > characters, injecting markup into any downstream consumer that parses the produced XML and renders the text content in a markup-sensitive context (HTML, SVG, RSS/Atom feeds). Both element text and attribute values are affected. This issue affects xml_builder: from 0.0.6 before 2.4.1.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-21
Last Modified
2026-08-21
Generated
2026-08-21
AI Q&A
2026-08-21
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
joshnuss xml_builder From 0.0.6 (inc) to 2.4.1 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-838 The product uses or specifies an encoding when generating output to a downstream component, but the specified encoding is not the same as the encoding that is expected by the downstream component.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an Inappropriate Encoding for Output Context issue in the xml_builder library. It occurs when the XmlBuilder.generate functions fail to properly escape literal ampersand characters (&) followed by entity-like tokens such as lt;, gt;, or amp;. Instead of escaping these sequences as &amp;lt;, they are emitted as &lt;, which downstream XML parsers decode back into markup characters like <. This allows attackers to inject malicious markup that bypasses upstream filters, potentially enabling content spoofing or cross-site scripting in contexts like HTML or RSS feeds.

Detection Guidance

To detect this vulnerability, inspect Elixir applications using xml_builder versions 0.0.6 to 2.4.0. Check for improperly escaped ampersands in XML output by reviewing generated XML files or logs for sequences like &lt;script&gt; instead of &amp;lt;script&amp;gt;. Use commands like grep to search for unescaped ampersands in XML content or check version numbers with mix deps.

Impact Analysis

If you use the affected xml_builder library versions (0.0.6 to 2.4.0), an attacker could craft input containing sequences like &lt;script&gt; that bypass upstream filters. When the XML is parsed downstream, these sequences become executable markup, potentially allowing script execution or content spoofing in web pages, feeds, or other markup-sensitive contexts. The impact depends on how the generated XML is consumed.

Compliance Impact

This vulnerability could lead to violations of GDPR or HIPAA if it enables unauthorized script execution or data exfiltration in systems handling sensitive data. GDPR requires protection against injection attacks that compromise data integrity, while HIPAA mandates safeguards against unauthorized access or modification of protected health information. Exploitation could result in non-compliance penalties or breaches.

Mitigation Strategies

Immediately upgrade xml_builder to version 2.4.1 or later. If upgrading is not possible, review and modify XML generation code to ensure all ampersands are escaped as &amp; regardless of context. Audit all XML outputs for potential injection vectors and apply input validation to prevent malicious input.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-47079. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart