CVE-2026-47080
Received Received - Intake

XML Injection in xml_builder via CDATA Handling

Vulnerability report for CVE-2026-47080, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-21

Last updated on: 2026-08-21

Assigner: EEF

Description

XML Injection vulnerability in joshnuss xml_builder (XmlBuilder module) allows Content Spoofing, XML Injection. This vulnerability is associated with program files lib/xml_builder.ex and program routines XmlBuilder.generate/1, XmlBuilder.generate/2, XmlBuilder.escape/1. The escape/1 clause for {:cdata, data} in lib/xml_builder.ex concatenates data verbatim between the CDATA opener <![CDATA[ and closer ]]> without rewriting or splitting on the embedded ]]> sequence. Because CDATA sections have no internal escape mechanism, the only safe way to embed arbitrary bytes is to split on ]]> and emit adjacent CDATA sections. An attacker who can supply input containing ]]> closes the CDATA section early; any bytes that follow are parsed as ordinary XML markup by downstream consumers, allowing injection of arbitrary elements, text, or entity references into the output document. This issue affects xml_builder: from 0.0.7 before 2.4.1.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-21
Last Modified
2026-08-21
Generated
2026-08-21
AI Q&A
2026-08-21
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
joshnuss xml_builder From 0.0.7 (inc) to 2.4.1 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-91 The product does not properly neutralize special elements that are used in XML, allowing attackers to modify the syntax, content, or commands of the XML before it is processed by an end system.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-47080 is an XML Injection vulnerability in the joshnuss xml_builder library. It allows attackers to inject malicious XML elements by exploiting unsanitized ]]> sequences in CDATA content. The library fails to escape these sequences, causing premature CDATA section closure and enabling arbitrary XML markup injection.

Detection Guidance

To detect this vulnerability, inspect applications using xml_builder versions 0.0.7 to 2.4.0. Check for improper handling of CDATA sections in lib/xml_builder.ex, particularly in XmlBuilder.generate/1, XmlBuilder.generate/2, and XmlBuilder.escape/1 routines. Look for unsanitized input containing ]]> sequences that could close CDATA sections prematurely.

Impact Analysis

This vulnerability could allow attackers to inject malicious XML elements, text, or entity references into XML documents generated by affected applications. This may lead to content spoofing, data manipulation, or further XML-based attacks if the output is parsed by downstream systems.

Compliance Impact

This vulnerability could potentially impact compliance with GDPR and HIPAA by enabling XML injection attacks that alter or spoof data. If exploited, it may lead to unauthorized data modification or disclosure, violating integrity and confidentiality requirements under these regulations.

Mitigation Strategies

Immediately upgrade xml_builder to version 2.4.1 or later. If upgrading is not possible, modify the escape/1 function to split CDATA content on ]]> and emit adjacent CDATA sections. Validate all XML output from xml_builder to ensure no malicious elements are injected.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-47080. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart