Executive brief
html_sanitize_ex is an Elixir library used to sanitize HTML content by removing potentially malicious tags and attributes. A vulnerability in its HTML5 scrubber allows remote attackers to load untrusted documents (via data URIs, protocol-relative URLs, or same-origin paths) into the data attribute of object elements, potentially leading to data exposure or unauthorized script execution if the application serves attacker-controlled content from the same origin.
Technical details
This is a URI validation bypass vulnerability in the HTML5 scrubber component. The object element was never registered through allow_tag_with_uri_attributes/3, and its only guard is a case-sensitive prefix match for "javascript:" URLs. This allows mixed-case variants (e.g., "JavaScript:", "JaVaScript:"), data: URIs, protocol-relative URLs, and same-origin paths to pass through sanitization. An attacker can inject these into the data attribute of an object element within sanitized HTML. While javascript: URLs do not execute through object data in modern browsers and data: documents load in an opaque origin, exploitation becomes viable if the target application serves attacker-controlled content from the same origin as the trusted page. The vulnerability affects versions 0.3.1 through 1.4.4 and 1.5.0-rc.0 through 1.5.2; version 1.4.5 and 1.5.3 provide fixes.
Affected products
- rrrene html_sanitize_ex 0.3.1 before 1.4.5 and 1.5.0-rc.0 before 1.5.3
Timeline
- 2026-08-06: disclosed