Executive brief
A vulnerability in the Phoenix LiveView library could allow an attacker to execute malicious code in a user's browser. This occurs when an application displays links provided by users, such as profile links or redirect targets. By adding a hidden character to the start of a link, an attacker can trick the system into allowing dangerous 'javascript:' links that would normally be blocked, potentially leading to account takeover or theft of sensitive session information.
Technical details
A cross-site scripting (XSS) vulnerability exists in Phoenix LiveView due to a flaw in the internal uri_scheme/1 helper within Phoenix.LiveView.Utils. The helper only detects a URI scheme if the first byte is an ASCII letter; if the input begins with an ASCII control character or space, it returns nil, causing the URL to be treated as a safe relative path. However, modern browsers following the WHATWG URL parser specification strip these leading characters before execution. An attacker can exploit this by providing a URL like ' javascript:alert(1)', which bypasses validation but executes JavaScript when clicked by a victim. This affects applications using the <.link href={...}> component with user-supplied data. The issue is fixed in version 1.2.7.
Affected products
- phoenixframework phoenix_live_view >= 1.2.2, < 1.2.7
Timeline
- 2026-07-13: advisory: GHSA-5cgh-g58j-m9cq published
- 2026-07-13: disclosed: CVE-2026-58228 published
- 2026-07-13: patched: Fix committed in version 1.2.7