CVE-2026-64941 PUBLISHED

Open redirect in Phoenix.LiveView.validate_local_url!/2 via ASCII tab, LF and CR

Assigner: EEF
Reserved: 09.08.2026 Published: 10.08.2026 Updated: 10.08.2026

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in phoenixframework phoenix_live_view allows an attacker to send a victim's browser to an origin of the attacker's choosing via a :to value containing ASCII tab, LF or CR.

redirect/2 validates :to through the private validate_local_url!/2 in lib/phoenix_live_view.ex, which is intended to guarantee the target is a path within the application. It rejects a leading // and any backslash, but not ASCII tab, LF or CR. Browsers strip those three characters before parsing a URL, so a value such as /<TAB>/example.com passes validation as a path and is then resolved as the scheme-relative URL //example.com. The live navigation functions share the guard but are not affected, because the client expands their target against the current origin. push_patch/2 is also affected before 0.7.0, which is when that expansion was added.

This issue affects phoenix_live_view: from 0.5.0 before 1.0.19, from 1.1.0-rc.0 before 1.1.33, and from 1.2.0-rc.0 before 1.2.9.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
CVSS Score: 2.1

Product Status

Vendor phoenixframework
Product phoenix_live_view
Versions Default: unaffected
  • affected from 0.5.0 to 1.0.19 (excl.)
  • affected from 1.1.0-rc.0 to 1.1.33 (excl.)
  • affected from 1.2.0-rc.0 to 1.2.9 (excl.)
Vendor phoenixframework
Product phoenix_live_view
Versions Default: unaffected
  • affected from b20dba3f65a380b2e4868dae03397f13d2daa070 to * (excl.)

Affected Configurations

The application must pass an externally influenced value as :to to redirect/2, or to push_patch/2 before 0.7.0, for example a return_to parameter carried through sign-in or a navigation target taken from a handle_event/3 payload.

Workarounds

Reject any untrusted value containing ASCII tab, LF or CR before passing it as :to to redirect/2, or to push_patch/2 before 0.7.0. Alternatively, map client-supplied navigation targets to a fixed set of known-good paths rather than forwarding the value.

Credits

  • Eurico Nicacio finder
  • Steffen Deusch remediation developer
  • José Valim remediation reviewer
  • Jonatan Männchen / EEF analyst

References

Problem Types

  • CWE-601 URL Redirection to Untrusted Site ('Open Redirect') CWE

Impacts

  • CAPEC-3 Using Leading 'Ghost' Character Sequences to Bypass Input Filters