Junglewise Threat Intelligence

CVE-2026-66829: rrrene html_sanitize_ex open redirect in meta refresh

CVE-2026-66829 · Severity: medium · CVSS 6.1 · Published 2026-08-06

Technologies: Rrrene Htmlsanitizeex, Rrrene Html Sanitize Ex. Vendors: Rrrene.

Executive brief

html_sanitize_ex is a library used to clean potentially malicious HTML content from user input. A vulnerability in its HTML5 scrubber allows attackers to inject meta refresh tags that redirect visitors to attacker-controlled websites, or inject meta directives like Content-Security-Policy headers. An attacker could trick users into visiting phishing sites or compromise website security policies through sanitized content.

Technical details

The HTML5 scrubber in html_sanitize_ex fails to remove or neutralize meta elements (specifically <meta http-equiv="refresh">) from sanitized output. Meta elements operate at the document level rather than fragment level, allowing injected meta tags to affect the entire page, including potential redirection or content security policy injection. The vulnerability requires no authentication and is exploitable via any content that passes through the library's sanitization function. An attacker can craft HTML containing a meta refresh element pointing to an arbitrary URL to achieve open redirect, or inject document-wide directives. The vulnerability affects versions 0.3.1 through 1.4.4 and 1.5.0-rc.0 through 1.5.2; patches are available in versions 1.4.5 and 1.5.3 or later.

Affected products

  • rrrene html_sanitize_ex 0.3.1 to 1.4.4, 1.5.0-rc.0 to 1.5.2

Timeline

  • 2026-08-06: disclosed

References

Related threats