VDB
KO

EEF-CVE-2026-66370

html_sanitize_ex HTML5 scrubber keeps attacker-supplied form-association attributes, allowing form hijacking

Quick fix

EEF-CVE-2026-66370 — html_sanitize_ex: upgrade to the fixed version with the command below.

mix deps.update html_sanitize_ex

Details

## Summary

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in the HTML5 scrubber in rrrene html\_sanitize\_ex allows an unauthenticated remote attacker to retarget a form already on the rendering page and receive whatever the victim submits, including credentials, via the form and formaction attributes on an <input> element in sanitized HTML. HTML's form attribute associates an input with any form on the page by its id even when the input sits outside that form, and formaction on a submit control overrides the owning form's action. Neither attribute receives a scheme check, so an absolute cross-origin URL survives sanitizing.

No script executes. The scrubber allows neither form nor button, so the attacker cannot introduce a form of their own and the rendering page must already contain a form carrying an id.

This issue affects html\_sanitize\_ex: from 0.3.1 before 1.5.3.

## Workaround

Sanitize with basic\_html/1, markdown\_html/1 or strip\_tags/1, none of which allow input, or define a custom scrubber that omits it.

Omitting the id attribute from the page's own forms, or giving them values an attacker cannot predict, removes the anchor the injected form attribute needs.

## Configuration

Only HtmlSanitizeEx.html5/1, and custom scrubbers declared with use HtmlSanitizeEx, extend: :html5, allow the input element, and the sanitized output must be rendered to other users.

The rendering page must also contain a form with an id, since that id is what the injected form attribute binds to.

Are you affected?

Enter the version of the package you're using.

Affected packages

Hex / html_sanitize_ex
Introduced in: 0.3.1 Fixed in: 1.5.3
Fix mix deps.update html_sanitize_ex

References