Executive brief
HTML::FormHandler is a Perl library used to generate and validate web forms. Versions before 0.410002 fail to properly escape field attributes when rendering HTML, allowing attackers to inject malicious attributes or JavaScript code into form fields if attribute values include untrusted data. This can lead to cross-site scripting (XSS) attacks affecting users who interact with affected forms.
Technical details
The vulnerability is a cross-site scripting (XSS) issue in the process_attrs method of HTML::FormHandler::Render::Util, which renders field attributes directly into HTML without proper escaping. The root cause is that attribute values derived from user-controlled data are not HTML-encoded before being inserted into double-quoted attribute contexts. An attacker can craft input such as `" onclick="alert(1)` to break out of the attribute and inject JavaScript. The fix (version 0.410002+) applies HTML entity encoding using encode_entities() with special attention to double quotes and ampersands within the attribute context. This vulnerability affects any form widget that uses process_attrs, including RadioGroup's render_option and wrap_radio methods.
Affected products
- Perl HTML::FormHandler before 0.410002
Timeline
- 2026-09-08: disclosed: CVE-2026-85630 published
- 2026-09-04: patched: Fix committed by Alexander Hartmaier in version 0.410002