CVE-2026-66296: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in lud oaskit
Improper Neutralization of Input During Web Page Generation (XSS) vulnerability in lud oaskit allows reflected cross-site scripting via the default HTML error handler. Oaskit.ErrorHandler.Default.format_reason/4 and Oaskit.ErrorHandler.Default.reason_to_html/1 in lib/oaskit/error_handler/default.ex render request-validation failures as an HTML page whenever the request's Accept header contains html, interpolating request-controlled strings into that page without HTML escaping. The unescaped values are object keys taken from a request body or from an object or deepObject query parameter, which appear in the JSON Schema error's instance path when a schema rejects them (for example under additionalProperties: false), and the raw Content-Type header, reflected in unsupported-media-type errors when it fails to parse. Because browsers send Accept: text/html on ordinary top-level navigation, a crafted GET link is sufficient to trigger the error page; no form submission, custom Content-Type, or attacker-controlled script on the victim's side is required. A payload such as filter[</code></h2><script>alert(document.domain)</script>]=x terminates the enclosing markup and the injected script executes in the origin of the application using oaskit, giving it access to that origin's cookies, session, and same-origin responses. Both HTML error rendering and the vulnerable handler are enabled by default: Oaskit.Plugs.ValidateRequest defaults :html_errors to true and :error_handler to Oaskit.ErrorHandler.Default, so applications following the documented usage are affected without any opt-in. This issue affects oaskit: from 0.1.0 before 0.14.1.
AI Analysis
Technical Summary
CVE-2026-66296 is a reflected XSS vulnerability in lud oaskit's default HTML error handler (Oaskit.ErrorHandler.Default). The issue arises because request-controlled strings, such as object keys from request bodies or query parameters, and raw Content-Type headers are interpolated into error pages without proper HTML escaping. This occurs in functions Oaskit.ErrorHandler.Default.format_reason/4 and reason_to_html/1 when rendering validation failure errors. Since browsers send Accept: text/html by default, an attacker can exploit this by sending a crafted GET request with malicious payloads in query parameters, causing script execution in the application's origin. The vulnerability affects all versions from 0.1.0 up to but not including 0.14.1, with the vulnerable error rendering enabled by default.
Potential Impact
Successful exploitation allows an attacker to execute arbitrary JavaScript in the context of the vulnerable application's origin. This can lead to theft of cookies, session tokens, and access to same-origin responses, potentially compromising user accounts and sensitive data. The vulnerability requires no authentication or user interaction beyond clicking a crafted link, increasing its risk.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, consider disabling the default HTML error handler or the :html_errors option in Oaskit.Plugs.ValidateRequest if feasible to prevent rendering of unescaped user input in error pages. Review application usage of oaskit and apply any vendor-provided updates or workarounds once published.
CVE-2026-66296: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in lud oaskit
Description
Improper Neutralization of Input During Web Page Generation (XSS) vulnerability in lud oaskit allows reflected cross-site scripting via the default HTML error handler. Oaskit.ErrorHandler.Default.format_reason/4 and Oaskit.ErrorHandler.Default.reason_to_html/1 in lib/oaskit/error_handler/default.ex render request-validation failures as an HTML page whenever the request's Accept header contains html, interpolating request-controlled strings into that page without HTML escaping. The unescaped values are object keys taken from a request body or from an object or deepObject query parameter, which appear in the JSON Schema error's instance path when a schema rejects them (for example under additionalProperties: false), and the raw Content-Type header, reflected in unsupported-media-type errors when it fails to parse. Because browsers send Accept: text/html on ordinary top-level navigation, a crafted GET link is sufficient to trigger the error page; no form submission, custom Content-Type, or attacker-controlled script on the victim's side is required. A payload such as filter[</code></h2><script>alert(document.domain)</script>]=x terminates the enclosing markup and the injected script executes in the origin of the application using oaskit, giving it access to that origin's cookies, session, and same-origin responses. Both HTML error rendering and the vulnerable handler are enabled by default: Oaskit.Plugs.ValidateRequest defaults :html_errors to true and :error_handler to Oaskit.ErrorHandler.Default, so applications following the documented usage are affected without any opt-in. This issue affects oaskit: from 0.1.0 before 0.14.1.
CVSS v4.0
Score 5.1medium
Affected software
lud
oaskit
lud
oaskit
cpe:2.3:a:lud:oaskit:*:*:*:*:*:elixir:*:*Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-66296 is a reflected XSS vulnerability in lud oaskit's default HTML error handler (Oaskit.ErrorHandler.Default). The issue arises because request-controlled strings, such as object keys from request bodies or query parameters, and raw Content-Type headers are interpolated into error pages without proper HTML escaping. This occurs in functions Oaskit.ErrorHandler.Default.format_reason/4 and reason_to_html/1 when rendering validation failure errors. Since browsers send Accept: text/html by default, an attacker can exploit this by sending a crafted GET request with malicious payloads in query parameters, causing script execution in the application's origin. The vulnerability affects all versions from 0.1.0 up to but not including 0.14.1, with the vulnerable error rendering enabled by default.
Potential Impact
Successful exploitation allows an attacker to execute arbitrary JavaScript in the context of the vulnerable application's origin. This can lead to theft of cookies, session tokens, and access to same-origin responses, potentially compromising user accounts and sensitive data. The vulnerability requires no authentication or user interaction beyond clicking a crafted link, increasing its risk.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, consider disabling the default HTML error handler or the :html_errors option in Oaskit.Plugs.ValidateRequest if feasible to prevent rendering of unescaped user input in error pages. Review application usage of oaskit and apply any vendor-provided updates or workarounds once published.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- EEF
- Date Reserved
- 2026-07-24T14:10:01.114Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6a70f0bfbf32cb7a341a7791
Added to database: 08/03/2026, 19:49:19 UTC
Last enriched: 08/03/2026, 20:06:35 UTC
Last updated: 09/17/2026, 22:01:37 UTC
Views: 40
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.