Executive brief
html_sanitize_ex is a library that removes potentially malicious HTML code from user input. An attacker can craft HTML containing form and formaction attributes that cause a legitimate form already on a web page to submit to a malicious site, potentially capturing user credentials and other sensitive data. The vulnerability affects multiple versions and does not require script execution or the attacker to add their own form.
Technical details
The vulnerability is an open redirect / form hijacking issue in the HTML5 scrubber component of html_sanitize_ex. The root cause is that the sanitizer fails to validate or strip the form and formaction attributes on input and submit elements. An attacker can use the form attribute to associate an input with any form on the page by its id, and the formaction attribute to override the target URL of a submit button, redirecting to a cross-origin URL. The attack requires a pre-existing form with an id on the rendering page but does not require authentication or script execution. Affected versions are 0.3.1 before 1.4.5 and 1.5.0-rc.0 before 1.5.3. Patches are available in versions 1.4.5 and 1.5.3 or later.
Affected products
- rrrene html_sanitize_ex 0.3.1 before 1.4.5, 1.5.0-rc.0 before 1.5.3
Timeline
- 2026-08-06: disclosed