EEF-CVE-2026-66370
html_sanitize_ex HTML5 scrubber keeps attacker-supplied form-association attributes, allowing form hijacking
빠른 조치
EEF-CVE-2026-66370 — html_sanitize_ex: 아래 명령으로 수정 버전으로 올리세요.
mix deps.update html_sanitize_ex 상세
## Summary
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in the HTML5 scrubber in rrrene html\_sanitize\_ex allows an unauthenticated remote attacker to retarget a form already on the rendering page and receive whatever the victim submits, including credentials, via the form and formaction attributes on an <input> element in sanitized HTML. HTML's form attribute associates an input with any form on the page by its id even when the input sits outside that form, and formaction on a submit control overrides the owning form's action. Neither attribute receives a scheme check, so an absolute cross-origin URL survives sanitizing.
No script executes. The scrubber allows neither form nor button, so the attacker cannot introduce a form of their own and the rendering page must already contain a form carrying an id.
This issue affects html\_sanitize\_ex: from 0.3.1 before 1.5.3.
## Workaround
Sanitize with basic\_html/1, markdown\_html/1 or strip\_tags/1, none of which allow input, or define a custom scrubber that omits it.
Omitting the id attribute from the page's own forms, or giving them values an attacker cannot predict, removes the anchor the injected form attribute needs.
## Configuration
Only HtmlSanitizeEx.html5/1, and custom scrubbers declared with use HtmlSanitizeEx, extend: :html5, allow the input element, and the sanitized output must be rendered to other users.
The rendering page must also contain a form with an id, since that id is what the injected form attribute binds to.
이 버전이 영향받나요?
사용 중인 패키지 버전을 입력하면 즉시 평가합니다.