Skip to main content
EPSS 0.2%top 84%

CVE-2026-66296: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in lud oaskit

0
Medium
VulnerabilityCVE-2026-66296cvecve-2026-66296cwe-79
Published: 08/03/2026 (08/03/2026, 19:04:30 UTC)
Source: CVE Database V5
Vendor/Project: lud
Product: oaskit

Description

Improper Neutralization of Input During Web Page Generation (XSS) vulnerability in lud oaskit allows reflected cross-site scripting via the default HTML error handler. Oaskit.ErrorHandler.Default.format_reason/4 and Oaskit.ErrorHandler.Default.reason_to_html/1 in lib/oaskit/error_handler/default.ex render request-validation failures as an HTML page whenever the request's Accept header contains html, interpolating request-controlled strings into that page without HTML escaping. The unescaped values are object keys taken from a request body or from an object or deepObject query parameter, which appear in the JSON Schema error's instance path when a schema rejects them (for example under additionalProperties: false), and the raw Content-Type header, reflected in unsupported-media-type errors when it fails to parse. Because browsers send Accept: text/html on ordinary top-level navigation, a crafted GET link is sufficient to trigger the error page; no form submission, custom Content-Type, or attacker-controlled script on the victim's side is required. A payload such as filter[</code></h2><script>alert(document.domain)</script>]=x terminates the enclosing markup and the injected script executes in the origin of the application using oaskit, giving it access to that origin's cookies, session, and same-origin responses. Both HTML error rendering and the vulnerable handler are enabled by default: Oaskit.Plugs.ValidateRequest defaults :html_errors to true and :error_handler to Oaskit.ErrorHandler.Default, so applications following the documented usage are affected without any opt-in. This issue affects oaskit: from 0.1.0 before 0.14.1.

CVSS v4.0

Score 5.1medium

Attack Vector
Network
Attack Complexity
Low
Attack Requirements
None
Privileges Required
None
User Interaction
Active
Vuln. Confidentiality
None
Vuln. Integrity
None
Vuln. Availability
None
Subsq. Confidentiality
Low
Subsq. Integrity
Low
Subsq. Availability
None
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N

Affected software

lud

oaskit

Affected versions
>=0.1.0 <0.14.1

lud

oaskit

oaskit
pkg:hex/oaskit
Affected versions
>=0.1.0 <0.14.1
GitHub Actionsmore threats →cve
lud/oaskit
pkg:github/lud/oaskit
CPE configurations
cpe:2.3:a:lud:oaskit:*:*:*:*:*:elixir:*:*

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/03/2026, 20:06:35 UTC

Technical Analysis

CVE-2026-66296 is a reflected XSS vulnerability in lud oaskit's default HTML error handler (Oaskit.ErrorHandler.Default). The issue arises because request-controlled strings, such as object keys from request bodies or query parameters, and raw Content-Type headers are interpolated into error pages without proper HTML escaping. This occurs in functions Oaskit.ErrorHandler.Default.format_reason/4 and reason_to_html/1 when rendering validation failure errors. Since browsers send Accept: text/html by default, an attacker can exploit this by sending a crafted GET request with malicious payloads in query parameters, causing script execution in the application's origin. The vulnerability affects all versions from 0.1.0 up to but not including 0.14.1, with the vulnerable error rendering enabled by default.

Potential Impact

Successful exploitation allows an attacker to execute arbitrary JavaScript in the context of the vulnerable application's origin. This can lead to theft of cookies, session tokens, and access to same-origin responses, potentially compromising user accounts and sensitive data. The vulnerability requires no authentication or user interaction beyond clicking a crafted link, increasing its risk.

Mitigation Recommendations

Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, consider disabling the default HTML error handler or the :html_errors option in Oaskit.Plugs.ValidateRequest if feasible to prevent rendering of unescaped user input in error pages. Review application usage of oaskit and apply any vendor-provided updates or workarounds once published.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
EEF
Date Reserved
2026-07-24T14:10:01.114Z
Cvss Version
4.0
State
PUBLISHED

Threat ID: 6a70f0bfbf32cb7a341a7791

Added to database: 08/03/2026, 19:49:19 UTC

Last enriched: 08/03/2026, 20:06:35 UTC

Last updated: 09/17/2026, 22:01:37 UTC

Views: 40

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses