CVE-2026-58228: Scheme validation bypass in Phoenix.LiveView.Utils leads to XSS via <.link>
Cross-site scripting vulnerability in phoenixframework phoenixliveview allows an attacker to bypass URL scheme validation and execute JavaScript in a victim's browser session.
The Phoenix.LiveView.Utils.validdestination!/2 and Phoenix.LiveView.Utils.validlivenavigationdestination!/2 functions in lib/phoenixliveview/utils.ex rely on an internal urischeme/1 helper that only detects a scheme when the input's first byte is an ASCII letter. Inputs beginning with an ASCII control character or space fall through to a nil-returning clause, causing the URL to be treated as a safe relative path.
Standard browsers implement the WHATWG URL parser, which strips leading C0 control and space characters before parsing. As a result, an input such as " javascript:alert(1)" is passed unchanged into <.link href={...}> and, when clicked, is parsed by the browser as a javascript: URL that executes attacker-controlled script in the victim's session.
Applications that render user-supplied URLs (for example profile links, redirect targets, or external references) via <.link href={...}> are affected.
This issue affects phoenixliveview: from 1.2.2 before 1.2.7.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-58228?
CVE-2026-58228 has a medium severity with a CVSS score of 5.1.
What type of vulnerability is CVE-2026-58228?
CVE-2026-58228 is a Cross-Site Scripting (XSS) vulnerability.
How does CVE-2026-58228 allow an attacker to exploit the system?
CVE-2026-58228 allows an attacker to bypass URL scheme validation, enabling JavaScript execution in a victim's browser session.
Which functions are affected by CVE-2026-58228?
The functions affected by CVE-2026-58228 are Phoenix.LiveView.Utils.valid_destination!/2 and Phoenix.LiveView.Utils.valid_live_navigation_destination!/2.
How can I mitigate the risk associated with CVE-2026-58228?
Mitigation for CVE-2026-58228 involves ensuring the use of patched versions of the phoenixframework phoenix_live_view.