PatchSiren cyber security CVE debrief
CVE-2026-66353 woylie CVE debrief
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in woylie doggo allows Reflected XSS. The vulnerability affects versions from 0.1.0 before 0.14.8 and is caused by the library's handling of date field values. Affected applications render <.field type='date'> over user-controlled params, allowing attackers to inject malicious code. The vulnerability can be exploited through the ordinary Phoenix form round-trip, where a failed validation re-renders the submitted value. To verify and validate user-controlled input for date fields, developers should review and update the doggo library to version 0.14.8 or later and implement additional security measures to prevent reflected XSS attacks. The ordinary Phoenix form round-trip can re-render submitted values, allowing attackers to inject malicious code if not properly validated. Security teams should review and validate the affected scope and severity of the vulnerability to ensure that it is properly mitigated. Compensating controls should be reviewed and implemented to prevent exploitation of the vulnerability. Monitoring and detection teams should review relevant logs and monitoring to detect potential exploitation of the vulnerability. Asset inventory and vulnerability management teams should review and update their asset inventory and vulnerability management processes to ensure that affected systems are properly mitigated. The vulnerability can be mitigated by updating the doggo library to version 0.14.8 or later and implementing additional security measures to prevent reflected XSS attacks. Affected systems should be reviewed and updated as soon as possible to prevent exploitation.
- Vendor
- woylie
- Product
- doggo
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-27
- Original CVE updated
- 2026-09-01
- Advisory published
- 2026-08-27
- Advisory updated
- 2026-09-01
Who should care
Developers and administrators using the doggo library in their applications should be aware of this vulnerability and take necessary steps to update and secure their systems. They should review and validate user-controlled input for date fields, implement additional security measures to prevent reflected XSS attacks, and verify the affected scope and severity of the vulnerability. Security teams and vulnerability management teams should also be aware of this vulnerability and track exceptions and retest remediated assets to ensure that the vulnerability is properly mitigated. Operators and platform administrators should review compensating controls for exposed systems while remediation is scheduled and verified. Asset inventory and monitoring teams should check relevant monitoring, detection, and logs for exposed assets that need extra review. Rollback and change window management teams should plan vendor-supported updates or mitigations through normal change control where exposure is confirmed. Source tracking and incident response teams should track the vulnerability and verify that affected systems are properly mitigated. The ordinary Phoenix form round-trip can re-render submitted values, allowing attackers to inject malicious code if not properly validated. To prevent reflected XSS attacks, additional security measures should be implemented, such as validating user input and encoding output. The vulnerability can be mitigated by updating the doggo library to version 0.14.8 or later and implementing additional security measures to prevent reflected XSS attacks. Affected systems should be reviewed and updated as soon as possible to prevent exploitation. Security teams should review and validate the affected scope and severity of the vulnerability to ensure that it is properly mitigated. Compensating controls should be reviewed and implemented to prevent exploitation of the vulnerability. Monitoring and detection teams should review relevant logs and monitoring to detect potential exploitation of the vulnerability. Asset inventory and vulnerability management teams should review and update their asset inventory and vulnerability management processes to ensure
Technical summary
The doggo library is vulnerable to reflected XSS attacks due to improper neutralization of input during web page generation. The vulnerability affects versions from 0.1.0 before 0.14.8 and is caused by the library's handling of date field values. Affected applications render <.field type='date'> over user-controlled params, allowing attackers to inject malicious code. The vulnerability can be exploited through the ordinary Phoenix form round-trip, where a failed validation re-renders the submitted value.
Defensive priority
Medium-priority defensive review recommended due to reflected XSS vulnerability in doggo library.
Recommended defensive actions
- Review and update doggo library to version 0.14.8 or later
- Verify and validate user-controlled input for date fields
- Implement additional security measures to prevent reflected XSS attacks
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
Evidence notes
The doggo library versions from 0.1.0 before 0.14.8 are vulnerable to reflected XSS attacks due to improper neutralization of input during web page generation. The vulnerability affects applications rendering <.field type='date'> over user-controlled params. Evidence from official sources indicates that the vulnerability can be exploited through the ordinary Phoenix form round-trip, where a failed validation re-renders the submitted value. To verify and validate user-controlled input for date fields, developers should review and update the doggo library to version 0.14.8 or later and implement additional security measures to prevent reflected XSS attacks.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-66353 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-66353
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-66353 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-66353
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://cna.erlef.org/cves/CVE-2026-66353.html
6b3ad84c-e1a6-4bf7-a703-f496b71e49db
-
Source reference
Unverified legacy reference
URL: https://github.com/woylie/doggo/commit/0161c976a114a4a4faee22d599b3fd5f147fc443
6b3ad84c-e1a6-4bf7-a703-f496b71e49db
-
Source reference
Unverified legacy reference
URL: https://github.com/woylie/doggo/security/advisories/GHSA-w9rp-cf93-86pj
6b3ad84c-e1a6-4bf7-a703-f496b71e49db
-
Source reference
Unverified legacy reference
URL: https://osv.dev/vulnerability/EEF-CVE-2026-66353
6b3ad84c-e1a6-4bf7-a703-f496b71e49db
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.