CVE-2026-48590 | joshnuss xml_builder 0.0.1/2.4.0 XmlBuilder lib/xml_builder.ex XmlBuilder.generate/XmlBuilder.element Name xml injection

SecurityVulns

A vulnerability was found in joshnuss xml_builder 0.0.1/2.4.0. It has been rated as critical. This issue affects the function XmlBuilder.generate/XmlBuilder.element of the file lib/xml_builder.ex of the component XmlBuilder. The manipulation of the argument Name leads to xml injection.

This vulnerability is traded as CVE-2026-48590. It is possible to initiate the attack remotely. There is no exploit available.

Upgrading the affected component is advised.VulDB Recent EntriesRead More