EEF-CVE-2026-47080
CDATA Section Breakout via Unsanitised ]]> in xml_builder
Quick fix
EEF-CVE-2026-47080 — xml_builder: upgrade to the fixed version with the command below.
mix deps.update xml_builder Details
## Summary
XML Injection vulnerability in joshnuss xml\_builder (XmlBuilder module) allows Content Spoofing, XML Injection.
This vulnerability is associated with program files lib/xml\_builder.ex and program routines XmlBuilder.generate/1, XmlBuilder.generate/2, XmlBuilder.escape/1.
The escape/1 clause for {:cdata, data} in lib/xml\_builder.ex concatenates data verbatim between the CDATA opener <!\[CDATA\[ and closer \]\]> without rewriting or splitting on the embedded \]\]> sequence. Because CDATA sections have no internal escape mechanism, the only safe way to embed arbitrary bytes is to split on \]\]> and emit adjacent CDATA sections. An attacker who can supply input containing \]\]> closes the CDATA section early; any bytes that follow are parsed as ordinary XML markup by downstream consumers, allowing injection of arbitrary elements, text, or entity references into the output document.
This issue affects xml\_builder: from 0.0.7 before 2.4.1.
Are you affected?
Enter the version of the package you're using.