PatchSiren cyber security CVE debrief
CVE-2026-42794 Cna CVE debrief
CVE-2026-42794 is a reflected cross-site scripting issue in absinthe_plug’s GraphiQL interface. The flaw is in js_escape/1, which escapes single quotes and newlines in the query GET parameter before embedding it in inline JavaScript, but does not escape backslashes. That leaves the string context breakable with a backslash-prefixed quote, allowing attacker-controlled JavaScript to run in a victim’s browser. The affected range is absinthe_plug 1.2.0 through 1.5.9, with a fix referenced in the upstream commit and the advisory pointing to 1.5.10 as the first safe version.
- Vendor
- Cna
- Product
- Unknown
- CVSS
- LOW 2.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-08
- Original CVE updated
- 2026-05-21
- Advisory published
- 2026-05-08
- Advisory updated
- 2026-05-21
Who should care
Teams running Elixir applications that expose Absinthe GraphiQL to browsers should review this promptly, especially if GraphiQL is reachable by untrusted users or used in production, staging, or shared internal environments.
Technical summary
The issue is a CWE-79 reflected XSS in the GraphiQL page generation path. When the query GET parameter is interpolated into an inline JavaScript string, js_escape/1 handles quotes and newlines but omits backslashes. A crafted value can use a backslash before a quote to escape the intended string literal and inject script execution. The CNA advisory and linked upstream references identify absinthe_plug versions from 1.2.0 before 1.5.10 as affected.
Defensive priority
Low, with faster attention if GraphiQL is exposed to non-trusted users or used in a browser context where session or administrative privileges matter.
Recommended defensive actions
- Upgrade absinthe_plug to 1.5.10 or later.
- If you maintain a pinned or forked version, backport the upstream escaping fix from the referenced commit.
- Review whether GraphiQL is exposed in any environment reachable by untrusted browsers and restrict access where practical.
- Validate that any custom inline JavaScript rendering paths do not embed unsafely escaped user input.
Evidence notes
This debrief is grounded in the supplied CNA advisory, the upstream issue and fix commit, the OSV record, and the NVD-modified source item. The CVE was published on 2026-05-08 and the provided source item shows NVD status as 'Awaiting Analysis' as of 2026-05-16. No exploit code or reproduction instructions are included.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-42794 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-42794
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-42794 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-42794
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://cna.erlef.org/cves/CVE-2026-42794.html
6b3ad84c-e1a6-4bf7-a703-f496b71e49db
-
Source reference
Unverified legacy reference
URL: https://github.com/absinthe-graphql/absinthe_plug/commit/23a0d5658d32420086711adf4ce8f05febb09963
6b3ad84c-e1a6-4bf7-a703-f496b71e49db
-
Source reference
Unverified legacy reference
URL: https://github.com/absinthe-graphql/absinthe_plug/issues/275
6b3ad84c-e1a6-4bf7-a703-f496b71e49db
-
Source reference
Unverified legacy reference
URL: https://osv.dev/vulnerability/EEF-CVE-2026-42794
6b3ad84c-e1a6-4bf7-a703-f496b71e49db
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.