Answer in brief
CVE-2026-47079 records a Low severity (CVSS 2.1) vulnerability in Round-trip Corruption via Improper Entity Escaping in xml_builder. The current sources do not mark it as known exploited. The current feed maps joshnuss/joshnuss/xml_builder (generic), joshnuss/xml_builder (generic), joshnuss/xml_builder (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 2.1. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps joshnuss/joshnuss/xml_builder (generic), joshnuss/xml_builder (generic), joshnuss/xml_builder (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| joshnuss/joshnuss/xml_buildergeneric | >=aae31e6e8ac837bcbb8afb816c0d14324b5cfe2b <c3390e2046ec297b3bb8c30d5779cdfd6508c275 | c3390e2046ec297b3bb8c30d5779cdfd6508c275 |
| joshnuss/xml_buildergeneric | >=aae31e6e8ac837bcbb8afb816c0d14324b5cfe2b <c3390e2046ec297b3bb8c30d5779cdfd6508c275 | c3390e2046ec297b3bb8c30d5779cdfd6508c275 |
| joshnuss/xml_buildergeneric | >=0.0.6 <2.4.1 | 2.4.1 |
Published upstream
Aug 21, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 24, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 21, 2026
Inappropriate Encoding for Output Context vulnerability in joshnuss xml_builder (XmlBuilder module) allows Content Spoofing, Cross-site Scripting. This vulnerability is associated with program files lib/xml_builder.ex and program routines XmlBuilder.generate/1, XmlBuilder.generate/2, XmlBuilder.escape_string/1, XmlBuilder.escape_entity/1. XmlBuilder.generate/1 does not escape literal & characters in text or attribute values when they are followed by an entity-like token (lt;, gt;, amp;, quot;, apos;). As a result, attacker-supplied input such as <script> is emitted verbatim into the serialized XML rather than being escaped to &lt;script&gt;. When a downstream XML parser later reads the document, it decodes the entity sequences into the literal characters <script>, promoting inert-looking text into real markup. This allows an attacker to bypass upstream filters that block raw < and > characters, injecting markup into any downstream consumer that parses the produced XML and renders the text content in a markup-sensitive context (HTML, SVG, RSS/Atom feeds). Both element text and attribute values are affected. This issue affects xml_builder: from 0.0.6 before 2.4.1.
Quoted source text, attributed separately from HOL analysis.