VDB
KO

EEF-CVE-2026-47080

CDATA Section Breakout via Unsanitised ]]> in xml_builder

Quick fix

EEF-CVE-2026-47080 — xml_builder: upgrade to the fixed version with the command below.

mix deps.update xml_builder

Details

## Summary

XML Injection vulnerability in joshnuss xml\_builder (XmlBuilder module) allows Content Spoofing, XML Injection.

This vulnerability is associated with program files lib/xml\_builder.ex and program routines XmlBuilder.generate/1, XmlBuilder.generate/2, XmlBuilder.escape/1.

The escape/1 clause for {:cdata, data} in lib/xml\_builder.ex concatenates data verbatim between the CDATA opener <!\[CDATA\[ and closer \]\]> without rewriting or splitting on the embedded \]\]> sequence. Because CDATA sections have no internal escape mechanism, the only safe way to embed arbitrary bytes is to split on \]\]> and emit adjacent CDATA sections. An attacker who can supply input containing \]\]> closes the CDATA section early; any bytes that follow are parsed as ordinary XML markup by downstream consumers, allowing injection of arbitrary elements, text, or entity references into the output document.

This issue affects xml\_builder: from 0.0.7 before 2.4.1.

Are you affected?

Enter the version of the package you're using.

Affected packages

Hex / xml_builder
Introduced in: 0.0.7 Fixed in: 2.4.1
Fix mix deps.update xml_builder

References