Junglewise Threat Intelligence

CVE-2026-64941: Phoenix phoenix_live_view open redirect via special characters

CVE-2026-64941 · Severity: info · CVSS 6.1 · Published 2026-08-10

Executive brief

Phoenix LiveView is a framework for building interactive web applications. The redirect/2 function in phoenix_live_view contains a URL validation flaw that allows attackers to craft malicious links containing hidden special characters (tab, line feed, carriage return) that bypass the security check. When a user follows such a link, their browser is silently redirected to an attacker-controlled website, enabling phishing attacks and credential theft.

Technical details

The vulnerability is an open redirect flaw in the validate_local_url!/2 function within lib/phoenix_live_view.ex. This private function is meant to ensure that redirect targets are local to the application by rejecting leading double-slashes and backslashes, but fails to filter ASCII tab (0x09), line feed (0x0A), and carriage return (0x0D) characters. Browsers automatically strip these whitespace characters before parsing URLs, allowing a path like /<TAB>/example.com to pass validation as a local path, then be resolved as the scheme-relative URL //example.com pointing to an external site. The redirect/2 function is affected in all versions, and push_patch/2 is also vulnerable before version 0.7.0. The attack requires only network access and no authentication; the victim simply needs to click a malicious link. Patches are available in versions 1.0.19, 1.1.33, and 1.2.9 for their respective release branches.

Affected products

  • phoenixframework phoenix_live_view 0.5.0 to 1.0.18, 1.1.0-rc.0 to 1.1.32, 1.2.0-rc.0 to 1.2.8

Timeline

  • 2026-08-10: disclosed
  • 2026-08-10: patched: Patches released for versions 1.0.19, 1.1.33, and 1.2.9

References