VDB
KO

EEF-CVE-2026-48590

Element and Attribute Names Injected Verbatim into XML Output in xml_builder

Quick fix

EEF-CVE-2026-48590 — xml_builder: upgrade to the fixed version with the command below.

mix deps.update xml_builder

Details

## Summary

XML Injection vulnerability in joshnuss xml\_builder (XmlBuilder module) allows Content Spoofing, XML Injection.

This vulnerability is associated with program files lib/xml\_builder.ex and program routines XmlBuilder.generate/1, XmlBuilder.generate/2, XmlBuilder.element/1, XmlBuilder.element/2, XmlBuilder.element/3.

Element names, attribute names, and doctype identifiers are interpolated verbatim into the serialized XML output without validation or escaping of structural characters (<, >, ", ', &). An attacker who can influence a name argument (for example, an element name derived from a JSON object key or an HTTP form field name) can inject arbitrary XML markup including extra elements, comments, and event-handler attributes into the output document.

This issue affects xml\_builder: from 0.0.1 before 2.4.1.

Are you affected?

Enter the version of the package you're using.

Affected packages

Hex / xml_builder
Introduced in: 0.0.1 Fixed in: 2.4.1
Fix mix deps.update xml_builder

References