EEF-CVE-2026-64941
Open redirect in Phoenix.LiveView.validate_local_url!/2 via ASCII tab, LF and CR
Quick fix
EEF-CVE-2026-64941 — phoenix_live_view: upgrade to the fixed version with the command below.
mix deps.update phoenix_live_viewDetails
## Summary
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in phoenixframework phoenix_live_view allows an attacker to send a victim's browser to an origin of the attacker's choosing via a `:to` value containing ASCII tab, LF or CR.
`redirect/2` validates `:to` through the private `validate_local_url!/2` in `lib/phoenix_live_view.ex`, which is intended to guarantee the target is a path within the application. It rejects a leading `//` and any backslash, but not ASCII tab, LF or CR. Browsers strip those three characters before parsing a URL, so a value such as `/<TAB>/example.com` passes validation as a path and is then resolved as the scheme-relative URL `//example.com`. The live navigation functions share the guard but are not affected, because the client expands their target against the current origin. `push_patch/2` is also affected before 0.7.0, which is when that expansion was added.
This issue affects phoenix_live_view: from 0.5.0 before 1.0.19, from 1.1.0-rc.0 before 1.1.33, and from 1.2.0-rc.0 before 1.2.9.
## Workarounds
Reject any untrusted value containing ASCII tab, LF or CR before passing it as `:to` to `redirect/2`, or to `push_patch/2` before 0.7.0. Alternatively, map client-supplied navigation targets to a fixed set of known-good paths rather than forwarding the value.
## Configurations
The application must pass an externally influenced value as `:to` to `redirect/2`, or to `push_patch/2` before 0.7.0, for example a `return_to` parameter carried through sign-in or a navigation target taken from a `handle_event/3` payload.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/phoenixframework/phoenix_live_view/security/advisories/GHSA-36m4-rm57-3prf[ADVISORY]
- https://cna.erlef.org/cves/CVE-2026-64941.html[WEB]
- https://github.com/phoenixframework/phoenix_live_view/commit/0b8c733133466912f81adecaea72b6712370242e[FIX]
- https://github.com/phoenixframework/phoenix_live_view/commit/1c164f83df0bb922dfff9c60d125da5b0cfd6619[FIX]
- https://github.com/phoenixframework/phoenix_live_view/commit/2068b304d71907064b159b6bc60c5ad85a876ecf[FIX]
- https://hex.pm/packages/phoenix_live_view[PACKAGE]