SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-48590

LOW · CVSS 2.1 EPSS 0.17% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-21 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

The XML Injection vulnerability in the XmlBuilder module allows attackers to manipulate element and attribute names in serialized XML output, leading to potential content spoofing and arbitrary XML markup injection. This flaw affects versions of xml_builder from 0.0.1 up to, but not including, 2.4.1, and should be prioritized by developers and organizations using this library to prevent exploitation through user-controlled input. Proper validation and escaping of structural characters in XML output are essential to mitigate this risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-48590
Severity
LOW
CVSS
2.1
EPSS
0.17%

Original NVD Description

XML Injection vulnerability in joshnuss xml_builder (XmlBuilder module) allows Content Spoofing, XML Injection. This vulnerability is associated with program files lib/xml_builder.ex and program routines XmlBuilder.generate/1, XmlBuilder.generate/2, XmlBuilder.element/1, XmlBuilder.element/2, XmlBuilder.element/3. Element names, attribute names, and doctype identifiers are interpolated verbatim into the serialized XML output without validation or escaping of structural characters (<, >, ", ', &). An attacker who can influence a name argument (for example, an element name derived from a JSON object key or an HTTP form field name) can inject arbitrary XML markup including extra elements, comments, and event-handler attributes into the output document. This issue affects xml_builder: from 0.0.1 before 2.4.1.