LOW
joshnuss
CVE published 2026-08-21
CVE-2026-47079
The xml_builder module, used for generating XML, has an Inappropriate Encoding for Output Context vulnerability. This issue allows for Content Spoofing and Cross-site Scripting attacks. The vulnerability is present in versions from 0.0.6 up to but not including 2.4.1. The root cause lies in the XmlBuilder.generate/1 function, which fails to properly escape literal & characters in text or attribute values [truncated]