XML Injection in joshnuss xml_builder Module Affects Content Management Solutions
CVE-2026-47080

2.1LOW

Key Information:

Vendor

Joshnuss

Vendor
CVE Published:
21 August 2026

What is CVE-2026-47080?

The XML Injection vulnerability in the joshnuss xml_builder module allows attackers to exploit the CDATA sections. This occurs due to the inadequacy of the escape function in handling the ']]>' sequence, which can lead to arbitrary XML elements being injected by prematurely closing the CDATA section. Unsanitized input can be misinterpreted as legitimate XML, enabling attackers to manipulate the output document by injecting unwanted elements or text, posing significant risks for content accuracy and integrity in applications utilizing this library.

Affected Version(s)

xml_builder 0.0.7 < 2.4.1

xml_builder 26766f884ed19adee1563522c7afb5f056a6f3b5

References

CVSS V4

Score:
2.1
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Peter Ullrich
Joshua Nussbaum
Jonatan Männchen / EEF
.