Junglewise Threat Intelligence

CVE-2026-66843: rrrene html_sanitize_ex object element URI bypass

CVE-2026-66843 · Severity: medium · CVSS 6.1 · Published 2026-08-06

Technologies: Rrrene Htmlsanitizeex, Rrrene Html Sanitize Ex. Vendors: Rrrene.

Executive brief

html_sanitize_ex is an Elixir library used to sanitize HTML content by removing potentially malicious tags and attributes. A vulnerability in its HTML5 scrubber allows remote attackers to load untrusted documents (via data URIs, protocol-relative URLs, or same-origin paths) into the data attribute of object elements, potentially leading to data exposure or unauthorized script execution if the application serves attacker-controlled content from the same origin.

Technical details

This is a URI validation bypass vulnerability in the HTML5 scrubber component. The object element was never registered through allow_tag_with_uri_attributes/3, and its only guard is a case-sensitive prefix match for "javascript:" URLs. This allows mixed-case variants (e.g., "JavaScript:", "JaVaScript:"), data: URIs, protocol-relative URLs, and same-origin paths to pass through sanitization. An attacker can inject these into the data attribute of an object element within sanitized HTML. While javascript: URLs do not execute through object data in modern browsers and data: documents load in an opaque origin, exploitation becomes viable if the target application serves attacker-controlled content from the same origin as the trusted page. The vulnerability affects versions 0.3.1 through 1.4.4 and 1.5.0-rc.0 through 1.5.2; version 1.4.5 and 1.5.3 provide fixes.

Affected products

  • rrrene html_sanitize_ex 0.3.1 before 1.4.5 and 1.5.0-rc.0 before 1.5.3

Timeline

  • 2026-08-06: disclosed

References

Related threats