PatchSiren

joshnuss CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

LOW joshnuss CVE published 2026-08-21

CVE-2026-47079

The xml_builder module, used for generating XML, has an Inappropriate Encoding for Output Context vulnerability. This issue allows for Content Spoofing and Cross-site Scripting attacks. The vulnerability is present in versions from 0.0.6 up to but not including 2.4.1. The root cause lies in the XmlBuilder.generate/1 function, which fails to properly escape literal & characters in text or attribute values [truncated]