EEF-CVE-2026-48590
Element and Attribute Names Injected Verbatim into XML Output in xml_builder
Quick fix
EEF-CVE-2026-48590 — xml_builder: upgrade to the fixed version with the command below.
mix deps.update xml_builder Details
## Summary
XML Injection vulnerability in joshnuss xml\_builder (XmlBuilder module) allows Content Spoofing, XML Injection.
This vulnerability is associated with program files lib/xml\_builder.ex and program routines XmlBuilder.generate/1, XmlBuilder.generate/2, XmlBuilder.element/1, XmlBuilder.element/2, XmlBuilder.element/3.
Element names, attribute names, and doctype identifiers are interpolated verbatim into the serialized XML output without validation or escaping of structural characters (<, >, ", ', &). An attacker who can influence a name argument (for example, an element name derived from a JSON object key or an HTTP form field name) can inject arbitrary XML markup including extra elements, comments, and event-handler attributes into the output document.
This issue affects xml\_builder: from 0.0.1 before 2.4.1.
Are you affected?
Enter the version of the package you're using.